Microsoft Application Insights Web Snippet
82%
Total Score
83
100
100
83
50
No build attestation or trusted-publisher provenance is present, leaving publication origin less independently verifiable. This is a transparency gap, but the active organization-owned repository and other project evidence partly compensate.
One contributor made about 84% of the 19 recent commits, creating concentrated maintenance risk. The Microsoft organization provides some handoff capacity, and two additional contributors remained active.
All seven workflows were analyzed, action references are fully pinned, and no untrusted checkout or script-injection paths were found. However, five workflows grant top-level write permissions and several high-confidence findings report packages installed outside lockfiles; the low-confidence cache findings are hygiene concerns only.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.