78%
Total Score
healthy
Active releases and contributors support this package, but the repository mismatch and workflow audit gaps reduce transparency.
No build attestation or staged publishing evidence was found, leaving release provenance less transparent despite the trusted publisher identity being GitHub.
The repository name does not match @vercel/fastify and its README does not mention the package, so the linkage is less transparent even though the repository is owned by the matching Vercel organization.
No type declarations are included, which reduces TypeScript ergonomics for consumers of this library. This is a consumer-experience gap rather than evidence of abandonment.
All 24 workflows were analyzed, but one file failed audit; 75 of 156 action references are unpinned, and high-confidence template-injection findings plus repeated ad hoc package installs create workflow hygiene concerns. No untrusted checkout or script-injection sink was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@vercel/node Version 23.0.1 | — | — |
@vercel/static-config Version 3.4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.