Type declarations, licensing, repository tests, release notes, and provenance are all in place, with regular releases and recent commits. The single active publisher, concentrated commits, and unpinned workflow actions warrant ongoing attention.
76%
Total Score
67
100
100
50
100
Only one registry publishing account is listed. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset this concentration.
Three contributors were active, but the top contributor made 12 of 14 recent commits, leaving maintenance substantially concentrated.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent.
All 19 analyzed action references are unpinned, and the audit found high-confidence ad hoc package installation; two workflows also grant top-level write permissions. No untrusted checkout or script injection was found, limiting the risk to workflow hygiene rather than a severe exposure.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-508122 @bbob/plugin-helper is vulnerable to Cross-Site Scripting (XSS) in versions 2.5.8 - 4.3.1. | 2.5.8 - 4.3.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
@bbob/types Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.