This package contains the shared types used across rrweb packages. rrweb makes extensive use of typescript types to enforce correctness and define the data API between packages. Check out the [Events](../../docs/events.md) doc for an introduction to the p
78%
Total Score
healthy
Healthy, backed by active releases and a current organization-owned repository.
A prepublish lifecycle script runs during publishing. This is not necessarily unsafe, but it adds release-process complexity that should be controlled by the repository's build workflow.
The repository name differs from the package name and its README does not mention @rrweb/types. The organization and monorepo context partly compensate, but package ownership is less directly transparent.
The repository uses established build and test tooling, but no security-scanning tool was detected; the missing scanning is a modest transparency gap rather than evidence of abandonment.
All seven workflows were analyzed with no untrusted checkout or script-injection findings, and all scope permissions at job level. However, one high-confidence medium-severity finding exposes the entire secrets context, and 18 of 25 action references are unpinned.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.