Transforms logical assignment operators into short-circuited assignments
20%
Total Score
critical
Unfit to use: the package is deprecated and explicitly replaced by @babel/plugin-transform-logical-assignment-operators.
The package is deprecated at package scope because the proposal is now part of ECMAScript, and the registry explicitly directs users to @babel/plugin-transform-logical-assignment-operators. This is a severe adoption risk despite the repository remaining active.
The package has had no releases in the last 12 months and its latest release was on April 4, 2023. The deprecation explains the lack of releases, but it confirms that this release line is no longer maintained.
The linked repository name does not match this package and its README does not mention the package, which creates a small ownership-transparency concern. The organization-owned monorepo context partly explains the mismatch.
All 13 workflows were analyzed with no untrusted checkout or script-injection counts, and most workflows use read-only or job-scoped permissions. However, 119 of 120 action references are unpinned, and the audit found high-confidence template-injection findings, so workflow hygiene remains a concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@babel/helper-plugin-utils Version ^7.20.2 | — | — |
@babel/plugin-syntax-logical-assignment-operators Version ^7.10.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.