Capacitor: Cross-platform apps with JavaScript and the web
84%
Total Score
healthy
Frequent releases, active organization-backed development, and provenance outweigh workflow hygiene gaps.
The package has 20 publishing accounts and 11 under the primary organization domain, though consumer-domain accounts such as jcesarmobile, chuckytuh, trevorlambert, and alexgerardojacinto add some account-hygiene caution.
The repository uses build tooling but reports no security-scanning tools, leaving less evidence of automated security hygiene than ideal.
All 40 analyzed action references are unpinned, and eight workflows grant top-level write permissions; high-confidence template-injection findings occur in publishing workflows, but no dangerous trigger or untrusted checkout was reported. These are meaningful workflow-hygiene concerns rather than a standalone release-blocking risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-728255 @capacitor/ios is vulnerable to Cross-Site Scripting (XSS) in versions 5.7.1 - 6.2.1, 7.0.0 - 7.6.8, 8.0.0 - 8.4.2 and 8.5.0 - 8.5.0. | 5.7.1 - 6.2.17.0.0 - 7.6.88.0.0 - 8.4.2 +1 more | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.