A Express.js server adapter for Bull-Board dashboard.
84%
Total Score
healthy
Healthy and actively maintained, with workflow pinning and audit issues as the main caveats.
The repository has no security policy file, leaving vulnerability reporting guidance unclear. This is a transparency gap, but active security scanning partly offsets it.
All seven workflows were analyzed, but all 32 action references are unpinned and high-confidence findings include unpinned container images; high-confidence adhoc package installs also appear in two workflows. The pull_request_target workflow has no untrusted checkout or script-injection sink, and the cache findings are low confidence, so this is workflow hygiene risk rather than a severe dependency verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ejs Version ^6.0.1 | — | — |
express Version ^5.2.1 | — | — |
@bull-board/ui Version 9.10.4 | — | — |
@bull-board/api Version 9.10.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.