Tools for working with package managers
82%
Total Score
healthy
Healthy, backed by active maintenance and releases, with workflow security hygiene as the main caveat.
One contributor made about 84% of recent commits, creating concentration risk, though 27 other contributors were active and the repository is organization-owned.
The repository name does not match the package and its README does not mention `@turbo/workspaces`, which creates some package-to-repository transparency concern; the organization-owned Turborepo monorepo context partly explains the mismatch.
All 12 workflows were analyzed with no untrusted checkout or script-injection findings, and 11 use read-only permissions. High-confidence template injection, inherited secrets, ad hoc package installation, and trusted-publishing findings are concrete workflow hygiene risks, though the workflow-run trigger has no identified untrusted sink.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ora Version 4.1.1 | — | — |
execa Version 5.1.1 | — | — |
semver Version 7.6.2 | — | — |
js-yaml Version 4.3.2 | — | — |
fs-extra Version 10.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.