AWS SDK for JavaScript Cognito Identity Client for Node.js, Browser and React Native
91%
Total Score
healthy
Frequent releases, active contributors, and AWS backing outweigh minor transparency and build-verification gaps.
The release has no attestation or trusted-publisher provenance, leaving the build and publication path less independently verifiable despite the package's strong maintenance evidence.
The linked repository name does not match the package and its README does not mention the package, which weakens package-to-source transparency. The AWS monorepo context makes a name mismatch ordinary, but the lack of a README mention remains a minor caution.
The repository uses established build and test tooling, including TypeScript, Vitest, and multiple bundlers. No security-scanning tools were detected, leaving a modest tooling gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.6.2 | — | — |
@smithy/core Version ^3.35.2 | — | — |
@aws-sdk/core Version ^3.978.2 | — | — |
@smithy/types Version ^4.19.0 | — | — |
@aws-sdk/types Version ^3.974.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.