82%
Total Score
healthy
Frequent releases and strong organizational maintenance outweigh workflow hygiene concerns.
No build attestation is provided, leaving publication provenance less transparent, though the trusted publisher identity is GitHub.
The artifact contains only LICENSE, dist/index.js, and package.json, making it minimal for consumers; the much larger repository provides the project context and development materials.
The package exposes no type declarations, which is a real integration drawback for consumers using typed tooling, although it does not by itself indicate abandonment.
All 24 workflows were analyzed and no untrusted checkout or script-injection sink was found, but 75 of 156 actions are unpinned and the audit reports high-confidence template-injection findings plus ad hoc package installs; trusted publishing is also not used. These are workflow hygiene concerns, not evidence that the release itself is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@vercel/node Version 23.0.1 | — | — |
@vercel/static-config Version 3.4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.