Metadata for VueUse functions
91%
Total Score
100
90
75
100
The repository name does not match this package and its README does not name it, which is a transparency caution under the signal rule. However, the organization-backed monorepo structure and package path make a sub-package relationship plausible.
The repository uses established build and test tooling, including TypeScript, Vitest, Vite, and Turbo. No security scanning tools were detected, leaving a modest security-process gap.
The repository has no SECURITY.md or equivalent policy, which reduces transparency about vulnerability reporting and response.
All workflows declare permissions, but two—including CI and publishing—have top-level write permissions. This is broader than a least-privilege setup, although no dangerous workflow pattern was detected.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.