Helper function to explode an assignable expression
58%
Total Score
100
100
85
83
50
No build attestation or trusted-publisher identity is recorded for this release, leaving publication provenance less transparent. The long-standing package and active organization repository provide partial context but not verifiable release provenance.
The package has 46 releases but none in the last 12 months; its latest registry release was over eight years ago. The actively maintained source repository partly compensates, but this specific release is notably stale.
The linked Babel monorepo neither matches the package name nor mentions it in its README, creating some uncertainty about package-to-repository mapping. The organization-backed monorepo context makes a subpackage relationship plausible but does not remove the gap entirely.
The project uses established build tooling, but the collected signal reports no security-scanning tools. The repository's other maintenance evidence partly compensates for that tooling gap.
All 13 workflows were analyzed with no untrusted checkout or script-injection sinks, but 119 of 120 action references are unpinned and the audit flags high-confidence template-injection patterns plus trusted-publishing usage. These are workflow hygiene and publishing risks, not evidence that the package itself is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
babel-types Version ^6.24.1 | — | — |
babel-runtime Version ^6.22.0 | — | — |
babel-traverse Version ^6.24.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.