82%
Total Score
healthy
Frequent releases, active contributions, and broad project participation outweigh workflow and repository-identification cautions.
No build attestation or trusted-publisher identity is recorded, leaving release provenance less independently verifiable; the active repository and release workflows partly compensate.
The repository name does not match @orval/mock and its README does not mention the package, creating a package-identification caution; the organization-backed monorepo context partly offsets it but does not remove the gap.
All seven workflows were analyzed, but all 23 action references are unpinned and four workflows grant top-level write permissions. High-confidence template-injection findings and trusted-publishing findings warrant workflow hygiene caution, while the low-confidence cache finding is not decisive.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-24132 @orval/mock is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 0.0.0 - 7.20.0 and 8.0.0-rc.0 - 8.0.3. | 0.0.0 - 7.20.08.0.0-rc.0 - 8.0.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
@orval/core Version 8.41.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.