Standalone build of Babel for use in non-Node.js environments.
82%
Total Score
healthy
Active maintenance and strong project backing outweigh workflow hygiene issues and the repository’s indirect package match.
The repository name does not match the package and its README does not mention @babel/standalone, creating some ambiguity about package ownership. The package is nevertheless published under the matching @babel namespace and points to the Babel organization repository.
The project uses established build tooling and has a repository security policy, although no security-scanning tools were detected. The policy and active workflow controls partly compensate for that gap.
All 14 workflows were analyzed with no untrusted checkouts or script-injection findings, and 11 use read-only permissions; however, 119 of 188 action references are unpinned, and the audit found high-confidence template-injection findings plus trusted-publishing usage. The low-confidence GITHUB_ENV and cache findings are hygiene concerns rather than standalone severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@babel/core Version ^8.0.7 | — | — |
@babel/parser Version ^8.0.7 | — | — |
@babel/generator Version ^8.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.