78%
Total Score
healthy
Active releases and maintenance outweigh a high-risk workflow token finding and missing security policy.
The repository name does not match the package and its README does not mention the package, which creates some provenance ambiguity; the mismatch is also consistent with this package being a sub-package of a monorepo.
No repository security policy was found, leaving disclosure and response guidance unclear for a browser-facing package.
All 11 workflows were analyzed with no untrusted checkouts, script injection, or unpinned actions, but publish-v2.yml has three high-confidence findings where an app token inherits blanket installation permissions. That is a meaningful supply-chain hygiene concern even without an untrusted trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.4.1 | — | — |
@amplitude/analytics-core Version 2.60.2 | — | — |
@amplitude/element-selector Version 0.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.