Helpers for confirming Solana transactions
68%
Total Score
caution
Usable with caveats: active maintenance is strong, but workflow risks and unclear package ownership reduce confidence.
The audit completed all 13 workflows but found high-confidence template-injection findings in package publishing, broad GitHub App token permissions, and one untrusted checkout in a pull_request_target workflow. Three of 27 action references are unpinned, adding a smaller reproducibility concern.
The repository name does not match the package and its README does not mention @solana/transaction-confirmation, so the package-to-repository relationship is not clearly demonstrated. The monorepo structure partly explains the name mismatch but not the absent README mention.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@solana/rpc Version 8.4.0 | — | — |
@solana/keys Version 8.4.0 | — | — |
@solana/errors Version 8.4.0 | — | — |
@solana/promises Version 8.4.0 | — | — |
@solana/addresses Version 8.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.