Programmatic API to update package.json
68%
Total Score
83
100
100
88
100
The repository had only 1 commit from 1 active maintainer in the last 3 months, which indicates limited recent development activity. The package still had 5 releases in the last 12 months, partly compensating for that weakness.
All 8 workflows were analyzed, but all 38 action references are unpinned, and two high-confidence template-injection findings remain in pull-request and release workflows. No untrusted checkout or script-injection path was found, so this is a caution rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
glob Version ^13.0.0 | — | — |
semver Version ^7.5.3 | — | — |
proc-log Version ^7.0.0 | — | — |
@npmcli/git Version ^8.0.0 | — | — |
hosted-git-info Version ^10.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.