88%
Total Score
healthy
Frequent releases and active organizational maintenance outweigh the repository's unpinned workflow actions.
All seven workflows were analyzed without file failures, but all 23 action references are unpinned and four workflows grant top-level write permissions. High-confidence template-injection findings and trusted-publishing findings warrant workflow review; the low-confidence cache-poisoning finding is hygiene rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jsesc Version ^3.0.0 | — | — |
@orval/core Version 8.41.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.