<
88%
Total Score
healthy
Frequent releases, active contributors, and build provenance support this release; all workflow actions are unpinned.
The project uses TypeScript, Vitest, and npm scripts for builds and tests, but no security-scanning tools were detected, leaving a modest security-process gap.
No repository security policy was detected, reducing transparency about vulnerability reporting and response expectations.
All 28 analyzed action references are unpinned, and the audit identifies high-confidence trusted-publishing usage; the workflows have no untrusted checkout or script-injection findings, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
picomatch Version ^4.0.4 | — | — |
@vue/shared Version ^3.5.0 | — | — |
alien-signals Version ^3.2.1 | — | — |
muggle-string Version ^0.4.1 | — | — |
path-browserify Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.