Internal helpers used by core Astro packages.
88%
Total Score
healthy
Active Astro monorepo backing and frequent releases support this internal package, despite workflow audit hygiene concerns.
A prepublish lifecycle script is present. This is a limited packaging risk, but the available build provenance and repository backing provide compensating transparency.
The repository name does not match the package and its README does not mention it, which is a caution under this signal; however, the package is an @astrojs internal helper in the Astro monorepo, making a monorepo subpackage explanation plausible.
Version 0.12.0 is a non-prerelease release, although the package is not at a stable major version and recent prereleases make its API less predictable.
All 21 workflows were analyzed, all 75 action references are pinned, and no untrusted checkout or script-injection sink was found. High-confidence template-injection and secrets-inherit findings remain workflow hygiene concerns, while the pull_request_target triggers have no reported sink.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10972 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @astrojs/internal-helpers is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.7.4 - 0.9.0. | 0.7.4 - 0.9.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
yaml Version ^2.9.1 | — | — |
shiki Version ^4.0.2 | — | — |
unified Version ^11.0.5 | — | — |
picomatch Version ^4.0.4 | — | — |
smol-toml Version ^1.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.