Package Health

@shopify/shopify-app-express

Healthy and suitable to depend on. It has frequent releases, active work from 10 contributors, clear documentation, tests in the source repository, and verified npm provenance. GitHub workflows have some permission and trust-boundary weaknesses, but the repository is active, backed by Shopify, and not archived or deprecated.

Latest 8.0.2NPMNPM

92%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Dangerous workflowscaution

Three workflows use pull_request_target, one performs an untrusted checkout, and one workflow_run workflow exists. No script-injection workflows were detected, so this is a workflow review concern rather than a severe package-health risk.

Token permissionscaution

Thirteen of 17 workflows lack top-level permission declarations, and two declare top-level write access. Although some workflows use read-only or job-level permissions, the inconsistent defaults weaken CI permission hygiene.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-37264
@shopify/shopify-app-express is vulnerable to Improper Verification of Cryptographic Signature in versions 2.2.4 - 7.0.1.
2.2.4 - 7.0.1
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
compare-versions
Version ^6.1.1
—
—
@shopify/shopify-api
Version ^15.0.0
—
—
@shopify/shopify-app-session-storage
Version ^7.0.0
—
—
@shopify/shopify-app-session-storage-memory
Version ^8.0.0
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
3 years ago
Unpacked Size
0.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform