Healthy and suitable to depend on. It has frequent releases, active work from 10 contributors, clear documentation, tests in the source repository, and verified npm provenance. GitHub workflows have some permission and trust-boundary weaknesses, but the repository is active, backed by Shopify, and not archived or deprecated.
92%
Total Score
100
100
100
80
100
Three workflows use pull_request_target, one performs an untrusted checkout, and one workflow_run workflow exists. No script-injection workflows were detected, so this is a workflow review concern rather than a severe package-health risk.
Thirteen of 17 workflows lack top-level permission declarations, and two declare top-level write access. Although some workflows use read-only or job-level permissions, the inconsistent defaults weaken CI permission hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-37264 @shopify/shopify-app-express is vulnerable to Improper Verification of Cryptographic Signature in versions 2.2.4 - 7.0.1. | 2.2.4 - 7.0.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
compare-versions Version ^6.1.1 | — | — |
@shopify/shopify-api Version ^15.0.0 | — | — |
@shopify/shopify-app-session-storage Version ^7.0.0 | — | — |
@shopify/shopify-app-session-storage-memory Version ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.