82%
Total Score
healthy
Active releases and strong project backing outweigh workflow pinning and security-policy gaps.
The repository uses established build tooling, but no security-scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance concern.
No repository security policy was detected. This is a documentation gap for reporting and handling vulnerabilities, though it is outweighed by the repository's active maintenance.
All 13 workflows were analyzed, with no untrusted checkouts or script-injection findings, but 76 of 79 action references are unpinned. High-confidence template-injection findings and a low-confidence ad hoc package installation warrant workflow hygiene caution, while no dangerous trigger was reported to corroborate them.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@formatjs/icu-skeleton-parser Version 2.1.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.