Node.js bindings for libddwaf
76%
Total Score
healthy
Healthy, with workflow hygiene concerns from unpinned actions and an archived action.
The repository name does not match the package name and its README does not mention the package, creating some uncertainty about package-to-repository linkage despite the matching DataDog organizational ownership.
The repository reports no security scanning tools, leaving a meaningful security-maintenance gap for a native security-related package.
No SECURITY policy is present, reducing transparency about vulnerability reporting and handling.
All 25 analyzed action references are unpinned, and the release workflow uses an archived action with high-confidence findings. The low-confidence cache findings are not independently material, while the lack of dangerous triggers or top-level write permissions is compensating evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
node-gyp-build Version ^3.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.