Types to work with Scalar packages
68%
Total Score
caution
Broad workflow credentials and a repository/package naming mismatch temper otherwise strong maintenance.
All 23 workflows use read-only permissions and all 166 analyzed actions are pinned, but the high-confidence github-app finding reports blanket installation permissions in release.yml; repeated secrets-inherit findings add further workflow hygiene risk.
Seven publishing accounts are present and five use the organization domain, while hwkr (hwkr.me) and hanspagel (hanspagel.com) are outside-domain accounts that add account-hygiene caution; organization backing partly compensates.
The repository name differs from the package name and its README does not mention @scalar/types; this is plausible for a monorepo subpackage but leaves package ownership less transparent.
Version 0.23.1 is not prerelease, although the package remains on a 0.x major version, so compatibility expectations are somewhat lower than for a stable-major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^4.4.3 | — | — |
nanoid Version ^5.1.6 | — | — |
type-fest Version ^5.8.0 | — | — |
@scalar/helpers Version 0.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.