Turns an AST into code.
61%
Total Score
100
100
79
83
The package has 94 releases and a four-day median interval historically, but its latest release was about eight years ago and there were no releases in the last 12 months. Active repository work partly offsets this, but the assessed registry version is stale.
The repository name does not match babel-generator and its README does not mention the package, so the package-to-repository link is less transparent. The organization-owned Babel monorepo context partly explains the mismatch but does not remove the documentation gap.
The project uses established build tooling, but no security-scanning tools were detected. The active organization and repository security policy provide some compensation, though this remains a minor transparency gap.
All 13 workflows were analyzed, but 119 of 120 action references are unpinned and the audit found high-confidence template-injection patterns plus a trusted-publishing finding. Pull-request-target workflows had no untrusted checkouts or script injections, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jsesc Version ^1.3.0 | — | — |
lodash Version ^4.17.4 | — | — |
source-map Version ^0.5.7 | — | — |
trim-right Version ^1.0.1 | — | — |
babel-types Version ^6.26.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.