General purpose glob-based configuration matching.
88%
Total Score
100
100
89
88
100
The project uses TypeScript, Vite, npm scripts, and Rollup, showing an established build process. No security-scanning tool was detected, which is a minor hygiene gap rather than evidence of abandonment.
Version 0.23.5 is not a stable-major release, but it is not a prerelease and recent releases contain no prerelease versions, so the maturity concern is limited.
All seven workflows were analyzed with no untrusted checkouts or script injection, and four use read-only permissions. However, 20 of 22 action references are unpinned, three workflows grant top-level write access, and high-confidence adhoc-package findings remain; these are workflow hygiene concerns without an untrusted trigger and sink combination.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^4.3.1 | — | — |
minimatch Version ^10.2.4 | — | — |
@eslint/object-schema Version ^3.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.