A set of utils for faster development of GraphQL tools
88%
Total Score
healthy
Healthy: frequent releases and recent repository activity outweigh minor workflow and package-linkage hygiene concerns.
Three publishing accounts use gmail.com addresses (urigo, ardatan, and enisdenjo), which is account-hygiene risk despite the primary the-guild.dev domain and five total publishers.
The repository is owned by a user account rather than an organization, so there is no explicit organizational handoff signal to offset contributor concentration.
One contributor made 62.5% of recent commits, which is concentrated, but seven other contributors were active during the same three-month period.
The repository name does not match the package name and its README does not mention this package, creating some uncertainty about the package-to-repository linkage; the package name mismatch can also occur for monorepo subpackages.
All four workflows were analyzed with no audit findings or untrusted checkouts. Eight of 22 action references are unpinned and two workflows have top-level write permissions, creating minor hygiene concerns without an observed exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.4.0 | — | — |
globby Version ^11.0.3 | — | — |
unixify Version ^1.0.0 | — | — |
@graphql-tools/utils Version ^12.0.3 | — | — |
@graphql-tools/import Version ^7.2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.