@intlify/core-base
88%
Total Score
healthy
Active releases, fresh repository activity, provenance, and a workflow hygiene concern shape this healthy release.
Four contributors were active recently, but the top contributor made 75% of commits. That concentration is a mild continuity concern, moderated by the organization-owned project and other active contributors.
All eight workflows were analyzed, all 40 action references are pinned, and no untrusted checkout or script-injection sink was found. A high-confidence template-injection finding warrants caution; the two low-confidence cache-poisoning findings are hygiene concerns, while wider permissions are not paired with an identified untrusted sink.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10497 @intlify/core-base is vulnerable to XSS vulnerability with Prototype Pollution in versions 9.3.0 - 9.14.1 and 10.0.0 - 10.0.4. | 9.3.0 - 9.14.110.0.0 - 10.0.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
@intlify/shared Version 11.4.14 | — | — |
@intlify/devtools-types Version 11.4.14 | — | — |
@intlify/message-compiler Version 11.4.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.