78%
Total Score
healthy
Active releases and broad maintenance outweigh workflow hygiene gaps and the package’s weak repository association.
The package has no attestation and does not use staged publishing, so release provenance is less transparent despite a trusted publisher identity being recorded.
The repository name does not match the package and its README does not mention the package. The monorepo structure makes a name mismatch ordinary, but the absence of a package mention leaves the package-to-repository association less transparent.
Version 0.1.79 is not on a stable major version, which implies API churn risk, but it is not a prerelease and recent releases show no prerelease usage.
All but one workflow were analyzed, but the audit found 15 high-confidence template-injection findings, 75 unpinned action uses out of 156, and numerous ad hoc package installs. No untrusted checkout or script-injection sink was found, so these are meaningful hygiene concerns rather than an automatic severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@vercel/backends Version 18.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.