Connector package for Amplitude SDKs
82%
Total Score
100
100
94
70
100
A prepublish lifecycle script is present; this is not inherently unsafe for consumers because it is generally a publish-time hook, but it adds build-pipeline complexity and warrants review.
The repository name does not match the package name and its README does not mention the package, creating a transparency concern that the linked repository may not directly correspond to this release; organization ownership partially mitigates, but does not remove, the mismatch.
No repository security policy was found, leaving vulnerability-reporting and disclosure expectations less transparent despite the presence of Semgrep scanning.
All 7 workflows lack top-level token permissions declarations, and none declare read-only permissions; although no workflow has top-level write permissions and two use job-level permissions, least-privilege configuration is not consistently explicit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.