Package Health

@datadog/native-appsec

Node.js bindings for libddwaf

Latest 11.0.3NPMNPM

76%

Total Score

healthy

Healthy, with workflow hygiene concerns from unpinned actions and an archived action.

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, creating some uncertainty about package-to-repository linkage despite the matching DataDog organizational ownership.

Repo toolingcaution

The repository reports no security scanning tools, leaving a meaningful security-maintenance gap for a native security-related package.

Security policycaution

No SECURITY policy is present, reducing transparency about vulnerability reporting and handling.

Workflow auditcaution

All 25 analyzed action references are unpinned, and the release workflow uses an archived action with high-confidence findings. The low-confidence cache findings are not independently material, while the lack of dangerous triggers or top-level write permissions is compensating evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
node-gyp-build
Version ^3.9.0
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
5 years ago
Unpacked Size
18 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform