82%
Total Score
75
100
94
75
One pull_request_target workflow exists, but no untrusted checkouts or script-injection patterns were detected across the five analyzed workflows.
Four contributors were active, but one account made about 83% of the recent commits; the organization backing provides some handoff capacity, but activity remains concentrated.
The repository has recent issues and pull requests, but it closed no issues and merged only one pull request in the last month, indicating some unresolved maintenance workload.
Four workflows lack top-level token permissions and one workflow requests top-level write access, leaving broader-than-necessary GitHub Actions permissions as a supply-chain hygiene concern.
Version 0.16.0 is not marked as a prerelease, but the recent prerelease share is 100%, so the pre-1.0 API may still change frequently.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@types/node Version ^25.6.0 | — | — |
discord-api-types Version 0.38.45 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.