84%
Total Score
100
100
90
83
50
No build attestation or trusted publisher provenance was reported, leaving artifact origin less independently verifiable despite the otherwise active project.
The repository name differs from the package name and its README does not mention this package. The mismatch can be normal for a monorepo, but the lack of a README reference leaves some uncertainty that the repository is the intended source.
The project uses established build tooling, but no security-scanning tools were detected. This is a modest transparency gap rather than evidence of abandonment.
All 11 workflows were analyzed, all 48 action references are pinned, and no untrusted checkout or script injection was found. The high-confidence use-trusted-publishing finding indicates registry publishing uses a long-lived token, so workflow supply-chain hygiene is not perfect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jest-mock Version 30.5.2 | — | — |
jest-util Version 30.5.1 | — | — |
@jest/types Version 30.5.1 | — | — |
@types/node Version * | — | — |
@jest/environment Version 30.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.