Skip to content

QuantumScan

mscdex/ssh2

mscdex/ssh2
87
risk score
50 findings · 30 files scanned

The ssh2 library contains 22 critical and 53 high-severity post-quantum cryptography vulnerabilities across 9 files. Core cryptographic protocols rely on quantum-vulnerable algorithms including RSA-2048, ECDSA, SHA-1 based key exchange, and legacy ciphers that will be broken by quantum computers. Immediate migration planning is required for regulatory compliance and long-term security.

Recent findingsView all findings →
FileAlgorithmSeverity
lib/protocol/constants.js:57SHA-1critical
lib/protocol/constants.js:59SHA-1critical
lib/protocol/constants.js:135SHA-1critical
lib/protocol/constants.js:138MD5critical
lib/protocol/constants.js:142SHA-1critical
lib/protocol/constants.js:143MD5critical
lib/protocol/constants.js:1123DES / TripleDEScritical
lib/protocol/constants.js:60SHA-1critical
test/test-keygen.js:25RSA key ≤ 2048 bitscritical
test/test-keygen.js:31RSA key ≤ 2048 bitscritical
Exposure by language
JavaScript50 · 100%
Compliance mapping
DORA
OK
NIS2
OK
NIST PQC
Gap
Exports for compliance
Share read-only link

Anyone with this link can view the risk score and top findings — no sign-in required. Source code stays private.

https://quantumscan.io/en/share/5ccf92e3-93bb-4279-888f-5e51e3fd3d3f
Add a badge to your README

Show your project's post-quantum readiness in the README. The badge updates automatically after every new scan.

Preview

Post-Quantum Readiness
Markdown
[![Post-Quantum Readiness](https://quantumscan.io/api/badge/mscdex/ssh2.svg)](https://github.com/mscdex/ssh2)
HTML
<a href="https://github.com/mscdex/ssh2"><img src="https://quantumscan.io/api/badge/mscdex/ssh2.svg" alt="Post-Quantum Readiness" /></a>

Add badge to your README

Show your quantum-safety score directly on GitHub.

QuantumScan badge preview
[![QuantumScan](https://quantumscan.io/api/badge/mscdex/ssh2.svg)](https://quantumscan.io/en/scan/5ccf92e3-93bb-4279-888f-5e51e3fd3d3f)

Save your results & track future changes

Create a free account to get drift alerts, compliance PDF exports, and scan history.

  • Weekly drift alerts when new vulnerabilities appear
  • Track risk score over time across all your repos
  • Export DORA / NIS2 compliance PDF for auditors

Free forever for design partners · No credit card