Statsig helps you move faster with feature gates (feature flags), and/or dynamic configs. It also allows you to run A/B/n tests to validate your new features and understand their impact on your KPIs. If you're new to Statsig, check out our product and cre
88%
Total Score
healthy
Healthy—frequent releases and an active organization-backed repository outweigh minor workflow and security-policy gaps.
The repository has no published security policy, which leaves vulnerability-reporting expectations unclear despite the presence of automated security scanning.
All six workflows were analyzed with no untrusted checkout or script-injection findings and all 17 action references pinned. However, two high-confidence low-severity adhoc-package findings and one workflow with top-level write permissions create a modest hygiene concern; the cache findings are low confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@statsig/client-core Version 3.33.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.