kjur/jsrsasign
text scan · 119 of 543 filesWhat was scanned
Scanner Shorstop 0.2.0 · text scan
Coverage 119 source files scanned of 543 in the repository; 8 skipped in test, vendored and build directories. What is excluded
Findings are starting points for investigation, not a security assessment. How scanning works
Total Cryptographic Assets
1489
Files Impacted
61
Quantum-Vulnerable Assets
49%
730 of 1489
Deprecated after 2030, disallowed after 2035 — NIST IR 8547
Quantum-Safe Assets
16%
237 of 1489
NIST-approved: FIPS 203 ML-KEM, 204 ML-DSA, 205 SLH-DSA
Quantum Readiness
Categories:
Post-Quantum Cryptography: NIST-approved PQC (Kyber, Dilithium, SPHINCS+)
Quantum-Safe Classical: Symmetric/hash with 256+ bit security (AES-256, SHA-256)
Quantum-Resistant Uncertain: Needs validation (AES-128, XMSS, some hash functions)
Quantum-Vulnerable: Broken by Shor's algorithm (RSA, ECDSA, DH)
Classically Weak: Broken TODAY (MD5, SHA-1, DES, RC4)
Unknown: Generic names, unidentifiable algorithms
By Algorithm Type
Algorithm Types:
Block Cipher: Symmetric encryption (AES, DES, ChaCha20)
Hash Function: One-way digest (SHA-256, MD5, BLAKE2)
Digital Signature: Asymmetric signing (RSA, ECDSA, Dilithium)
Message Authentication: MAC codes (HMAC, CMAC, Poly1305)
Key Derivation: KDF functions (PBKDF2, Argon2, HKDF)
Public Key Encryption: Asymmetric encryption (RSA, Kyber)
Public Key Cipher: Public key cryptography (RSA, ElGamal)
Key Exchange: Key agreement (ECDH, X25519, Kyber-KEM)
Authenticated Encryption: Combined encryption+MAC (AES-GCM, ChaCha20-Poly1305)
Extendable-Output Function: Variable-length output (SHAKE128, SHAKE256)
Other: Miscellaneous or unclassified algorithms
By Purpose
Purpose Types:
Encryption: Protect data confidentiality
Decryption: Recover original data
Digital Signing: Prove authenticity and integrity
Signature Verification: Validate digital signatures
Key Generation: Create cryptographic keys
Key Agreement: Establish shared secrets
Hashing: Generate message digests
Other: Miscellaneous or unclassified operations
Cryptographic Assets
Export
Cryptographic Bill of Materials (CycloneDX)
| Name | Primitive | Functions | File:Line | Risk |
|---|---|---|---|---|
| MD5-digest | hash | digest | ext/cj/md5.js:26 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5.js:28 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5.js:234 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5.js:235 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5.js:237 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5.js:253 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5_min.js:2 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5_min.js:7 | Classically weak |
| MD5-digest | hash | digest | ext/cj/md5_min.js:12 | Classically weak |
| SHA-1-digest | hash | digest | ext/cj/pbkdf2.js:14 | Classically weak |
Page 1 of 149