This package exports the Prisma Engines version to be downloaded from Prisma CDN.
78%
Total Score
100
100
83
83
100
A README is present and explicitly warns that this is an internal-use package whose release cycle can introduce breaking changes without warning. Missing tests and a changelog are expected packaging gaps and are not penalized.
The repository uses TypeScript build tooling, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap rather than evidence of poor maintenance by itself.
The assessed release is a prerelease and all recent releases are prereleases, consistent with the README warning that breaking changes may arrive without notice. That lowers consumer predictability even though the major version is stable.
Both workflows were analyzed without untrusted checkouts, script injection, or write permissions, and one scopes permissions at job level. However, all 11 action references are unpinned and the publish workflow installs a package outside a lockfile, creating reproducibility and workflow-supply-chain hygiene concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.