JSON AST parser, tokenizer, printer, traverser.
88%
Total Score
100
100
95
70
100
A prepare install lifecycle script is present, which adds execution during installation, but the signal provides no evidence that it is dangerous and the repository shows ordinary build and release automation.
No build tool or security scanning tool was detected in the repository, leaving a security and engineering-hygiene gap despite other evidence of structured CI and release workflows.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
One workflow lacks top-level permissions and two workflows declare top-level write access, creating permissions-hygiene concerns; these are mitigated by the absence of detected dangerous workflow patterns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.