Microsoft Application Insights XHR dependencies plugin
86%
Total Score
healthy
Frequent releases and active Microsoft-backed maintenance outweigh concentrated commits and workflow hygiene concerns.
No build attestation or trusted-publisher provenance is reported, leaving publication origin less independently verifiable than it could be. This is a transparency gap, not evidence that the release is unsafe.
All seven workflows were analyzed, all 18 action references are pinned, and no untrusted checkout or script-injection paths were found. However, five workflows use top-level write permissions and high-severity cache-poisoning findings have low confidence, while high-confidence adhoc-package findings show installs outside a lockfile; together these are workflow hygiene cautions rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@nevware21/ts-async Version >= 0.5.5 < 0.6.0 | — | — |
@nevware21/ts-utils Version >= 0.14.0 < 2.x | — | — |
@microsoft/dynamicproto-js Version ^2.0.3 | — | — |
@microsoft/applicationinsights-shims Version 3.0.1 | — | — |
@microsoft/applicationinsights-core-js Version 3.4.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.