82%
Total Score
healthy
Active, well-supported project with a repository-reference mismatch and incomplete workflow hygiene.
No build attestation is present, leaving publication provenance less verifiable even though the trusted publisher identity is GitHub.
The repository name does not match the package and its README does not mention @vercel/static-build, so the package-to-repository association is less transparent; the monorepo context partly explains the name mismatch but not the missing README mention.
All 24 workflows were analyzed, but one file failed auditing; 75 of 156 action references are unpinned, and high-confidence template-injection findings plus ad hoc package installs indicate workflow hygiene gaps. The workflow_run trigger is in a different path from the reported template-injection findings, so this is caution rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ts-morph Version 12.0.0 | — | — |
@vercel/static-config Version 3.4.4 | — | — |
@vercel/gatsby-plugin-vercel-builder Version 2.2.71 | — | — |
@vercel/gatsby-plugin-vercel-analytics Version 1.0.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.