babel's modular runtime helpers
88%
Total Score
healthy
Active project with strong release cadence; workflow pinning and package-repository linkage need attention.
The repository name does not match @babel/runtime and its README does not mention the package. This is a caution because the link is not explicit, although the organization-backed Babel monorepo context partly offsets the concern.
The project uses established build tooling, but no security-scanning tools were detected. The repository's separate security policy and workflow audit provide some compensating transparency.
All 14 workflows were analyzed, with 11 using read-only permissions, but 119 of 188 action references are unpinned. High-confidence template-injection findings and use of long-lived publishing credentials add workflow hygiene and release-process risk; the low-confidence GITHUB_ENV and cache findings are weaker evidence.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.