91%
Total Score
healthy
Healthy release, backed by active organization maintenance; only workflow hygiene and a missing security policy temper confidence.
This release has no registry attestation or trusted-publisher provenance, leaving the build-to-published-artifact chain less independently verifiable.
No repository security policy was found, which reduces the transparency of vulnerability reporting and handling despite the presence of CodeQL and Dependabot tooling.
All six workflows were analyzed and all 15 action references are pinned, but three workflows grant top-level write permissions and a high-severity cache-poisoning finding was reported with low confidence; the archived action finding is medium severity with high confidence.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-965960 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @datadog/browser-core is vulnerable to Prototype Pollution in versions 1.25.0 - 7.3.0. | 1.25.0 - 7.3.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@datadog/js-core Version 0.0.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.