The AsyncAPI generator. It can generate documentation, code, anything!
88%
Total Score
100
50
100
80
100
Eight workflows use pull_request_target and one checks out untrusted content, creating elevated CI supply-chain risk even though no script-injection or workflow-run patterns were detected.
There are 26 runtime dependencies, including substantial parser, filesystem, template, and CLI components; this is a meaningful maintenance surface, but it is consistent with a full-featured generator.
Twenty-one workflows declare read-only permissions, but eight omit top-level permissions and one grants top-level write access, leaving avoidable privilege-management gaps in CI.
| Dependency | Last Release | Score |
|---|---|---|
ajv Version ^8.12.0 | — | — |
semver Version ^7.3.2 | — | — |
js-yaml Version ^4.3.2 | — | — |
ts-node Version ^10.9.1 | — | — |
fs.extra Version ^1.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.