Package Health

@bbob/plugin-helper

Type declarations, licensing, repository tests, release notes, and provenance are all in place, with regular releases and recent commits. The single active publisher, concentrated commits, and unpinned workflow actions warrant ongoing attention.

Latest 4.4.1NPMNPM

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this concentration.

Repo bus factorcaution

Three contributors were active, but the top contributor made 12 of 14 recent commits, leaving maintenance substantially concentrated.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations less transparent.

Workflow auditcaution

All 19 analyzed action references are unpinned, and the audit found high-confidence ad hoc package installation; two workflows also grant top-level write permissions. No untrusted checkout or script injection was found, limiting the risk to workflow hygiene rather than a severe exposure.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-508122
@bbob/plugin-helper is vulnerable to Cross-Site Scripting (XSS) in versions 2.5.8 - 4.3.1.
2.5.8 - 4.3.1
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@bbob/types
Version *
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
8 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform