Generate errors that contain a code frame that point to source locations.
72%
Total Score
100
100
89
88
100
The repository name does not match the package and its README does not mention @babel/code-frame, which creates package-identity ambiguity; the Babel organization and monorepo context reduce but do not eliminate that concern.
The project uses established build tooling, but no security scanning tools were detected; the documented security policy and active maintenance partly compensate for that hygiene gap.
All 13 workflows were analyzed with no untrusted checkouts or script-injection sinks, but 119 of 120 action references are unpinned and the audit flags high-confidence template-injection patterns plus trusted-publishing usage. These workflow weaknesses warrant caution even with mostly scoped permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
js-tokens Version ^10.0.0 | — | — |
@babel/helper-validator-identifier Version ^8.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.