Babel command line
80%
Total Score
100
100
89
83
100
The repository name does not match the package and its README does not mention @babel/node, which makes package ownership less transparent; the organization-backed Babel monorepo partly compensates.
The project uses established build tooling, but no security-scanning tools were detected; the repository's security policy partly compensates for that gap.
All 13 workflows were analyzed, but 119 of 120 action references are unpinned, and high-confidence template-injection findings appear in release-related workflows. The audit found no untrusted checkout or script-injection count, so this is a hygiene concern rather than a standalone severe health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
core-js Version ^3.48.0 | — | — |
v8flags Version ^4.0.1 | — | — |
commander Version ^14.0.2 | — | — |
@babel/register Version ^8.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.