Module Federation Data Prefetch
57%
Total Score
caution
Usable with caveats: the package README directs users to a replacement despite active project maintenance.
The package includes type declarations, tests and a changelog in the source project, but its 133-character README explicitly says the package is deprecated and recommends a data solution. That guidance materially lowers confidence for new dependencies.
The linked repository name does not match the package and its README does not mention the package. A name mismatch can be normal for a monorepo, but the lack of an explicit package mention leaves ownership of this artifact less transparent.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, although active development and automated security scanning provide some compensation.
All 26 workflows were analyzed and all 113 action references are pinned, with no untrusted checkout or script-injection counts. However, high-confidence template-injection findings and repeated high-confidence secrets-inherit findings are meaningful workflow hygiene concerns; the low-confidence cache finding and low-severity ad hoc package install add little weight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@module-federation/sdk Version 2.3.3 | — | — |
@module-federation/runtime Version 2.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.