@supabase/supabase-js 2.116.0 appears healthy and suitable for dependency use. It has a long release history with 832 releases and 409 releases in the last 12 months, active repository development with 102 commits and 18 active maintainers in the last 3 months, current non-archived status, organization backing, repository tests and changelog coverage, MIT licensing, type declarations, build provenance, and no install-time lifecycle scripts. The main residual concern is workflow permission hygiene: several workflows lack top-level permissions and four declare top-level write access, although the analyzed workflows show no pull-request-target, untrusted-checkout, workflow-run, or script-injection risks. The high recent prerelease share also warrants some caution, but the assessed release is a stable major and is not deprecated.
94%
Total Score
100
100
95
90
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@supabase/auth-js Version 2.116.0 | — | — |
@supabase/storage-js Version 2.116.0 | — | — |
@supabase/realtime-js Version 2.116.0 | — | — |
@supabase/functions-js Version 2.116.0 | — | — |
@supabase/postgrest-js Version 2.116.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.