Native bindings for Rollup
84%
Total Score
healthy
Frequent releases, active project backing, and npm provenance outweigh concentrated commits and minor workflow hygiene concerns.
The repository name does not match this platform-specific package and its README does not mention the exact package, a caution for package-to-repository traceability. However, the organization-backed Rollup monorepo context makes a subpackage relationship plausible.
All seven workflows were analyzed and all 64 action references are pinned, with no untrusted checkouts or script injection detected. The audit found low-confidence cache-poisoning patterns and three high-confidence low-severity ad hoc package installs, which are minor workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.