A CJS bundled version of @angular/compiler
78%
Total Score
healthy
Active maintenance and provenance are strong, but workflow hygiene and an indirect package reference reduce confidence.
The repository name does not match this package and its README does not mention it, so the package-to-repository relationship is less transparent; the organization-owned monorepo context partly offsets that concern.
The project uses established build tooling, including TypeScript, Nx, esbuild, Vite, and SWC, but no security scanning tool was detected; the missing scanner is a modest transparency gap.
All eight workflows were analyzed and use read-only permissions, with no untrusted checkouts or script-injection findings. However, all 42 action references are unpinned, and high-confidence template-injection and unsound-condition findings plus adhoc package installs weaken release-workflow hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.