Tools for working with PGlite databases
82%
Total Score
healthy
Healthy: frequent releases and active, broadly distributed maintenance outweigh workflow pinning and security-policy gaps.
The repository name does not match the package name and its README does not mention this package. While a name mismatch is normal for a monorepo, the missing README mention leaves package ownership less explicit.
The repository uses TypeScript, npm scripts, and tsup for its build, but no security-scanning tools were detected. The established build tooling is positive, while the missing scanning is a minor transparency gap.
No repository security policy was found. This does not show a defect in the release, but it reduces transparency about how vulnerabilities are reported and handled.
The workflow audit completed cleanly with no untrusted checkouts, script injections, or audit findings, but the workflow has top-level write permissions and all 93 action references are unpinned. Those choices weaken CI supply-chain hygiene without showing an active exploit path.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.