A library for installing and finding packages in a project
88%
Total Score
healthy
Healthy, backed by active maintenance and broad organizational ownership.
The linked repository name does not match the package and its README does not mention @expo/package-manager, so ownership of this subpackage is less transparent; the organization-backed monorepo partly compensates for the mismatch.
The audit is incomplete because only 30 of 53 workflows were analyzed, and it found high-confidence template-injection patterns plus lower-confidence cache findings and high-confidence ad hoc package installs. No untrusted checkout or script-injection sink was reported, and all 137 analyzed action references are pinned, limiting the concern to workflow hygiene rather than a severe release risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ora Version ^3.4.0 | — | — |
chalk Version ^4.0.0 | — | — |
@expo/json-file Version ^11.0.1 | — | — |
npm-package-arg Version ^11.0.0 | — | — |
@expo/spawn-async Version ^1.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.