A Progressive React Framework for modern web development.
88%
Total Score
100
100
90
75
50
No build attestation or trusted-publisher provenance is available. This is a transparency gap, but the package has strong independent release and repository activity that partly offsets it.
The repository name does not match the package and its README does not mention @modern-js/node-bundle-require, so the package's connection to the linked monorepo is less transparent. The mismatch is plausible for a monorepo sub-package but still warrants caution.
The project uses build tooling, but no security-scanning tools were detected. That is a modest assurance gap, partially offset by the active organization-backed project and workflow audit.
No repository security policy was found, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not by itself evidence of abandonment.
All 10 workflows were analyzed with no untrusted checkouts, script injection, high-severity findings, or unpinned action references. Six high-confidence low-severity adhoc-package findings indicate some workflows install packages outside a lockfile, a hygiene concern rather than a severe release risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
esbuild Version 0.25.5 | — | — |
@swc/helpers Version ^0.5.17 | — | — |
@modern-js/utils Version 2.70.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.