The FreeBSD ARM 64-bit binary for esbuild, a JavaScript bundler.
86%
Total Score
83
90
67
100
One contributor made about 91% of recent commits, creating concentration risk. Three additional contributors were active, which partly offsets but does not remove that concern.
The repository name does not match this platform-specific package and its README does not explicitly mention the package, creating a provenance ambiguity. The package README does point consumers to this repository, which partly supports the link.
The project uses build tooling, but no security-scanning tools were detected. This is a transparency and hygiene gap rather than evidence of abandonment.
No repository security policy was found. That weakens vulnerability-reporting transparency, although active commits and releases provide compensating maintenance evidence.
All four workflows were analyzed, all 19 action references are pinned, and no untrusted checkout or script injection was found. However, the audit found a high-severity low-confidence cache finding, an archived action, and several high-confidence ad hoc package installations; one workflow also grants top-level write access.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.