Typed artifacts, release notes, and a licensed package make integration straightforward. The repository remains active with 11 contributors and security tooling; workflow review found one untrusted checkout and a high-confidence template-injection hygiene issue.
88%
Total Score
100
100
94
83
100
The repository name differs from the package and its README does not mention this package, creating some uncertainty about package-to-repository correspondence; the organization-owned monorepo context partly explains the mismatch but does not remove it.
The audit covered all 16 workflows and found one untrusted checkout plus a high-confidence template-injection finding; the low-confidence cache finding is hygiene only, while three unpinned actions and some broad permissions add minor exposure.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-492382 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @shopify/shopify-app-react-router is vulnerable to Improper Verification of Cryptographic Signature in versions 0.1.0 - 1.2.1. | 0.1.0 - 1.2.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
isbot Version ^5.2.0 | — | — |
compare-versions Version ^6.1.1 | — | — |
@shopify/shopify-api Version ^15.0.0 | — | — |
@shopify/admin-api-client Version ^2.0.0 | — | — |
@shopify/storefront-api-client Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.