It also ships type declarations, release notes, and npm provenance, with a small runtime dependency set. Workflow permissions and unpinned actions need attention, while the missing package-name reference makes repository ownership less transparent.
82%
Total Score
100
100
90
50
100
The package defines postinstall and prepack scripts, which add installation and packaging behavior that consumers should understand before adoption.
The repository name does not match the package name and its README does not mention @stream-io/node-sdk, so the package-to-source relationship is less transparent despite the organization backing it.
The project uses TypeScript, Vite, and npm scripts, but no security scanning tools were detected; that is a modest repository-hygiene gap rather than an adoption blocker.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All five workflows were analyzed without untrusted checkouts or script injection, but all 13 action references are unpinned, two workflows grant top-level write permissions, and one archived action was found. These are workflow-hygiene concerns, not evidence of an unsafe release on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jsonwebtoken Version ^9.0.3 | — | — |
@types/jsonwebtoken Version ^9.0.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.