Compile ES2015 spread to ES5
64%
Total Score
100
100
81
83
The package has had no release in more than eight years, despite 35 releases overall. This strongly limits confidence that this specific release will receive fixes, although the long prior release history shows it was once maintained.
The repository neither matches the package name nor mentions it in its README. Although name differences are normal for monorepo subpackages, this lack of an explicit mention leaves package ownership less transparent.
The repository uses established build tooling, but no security-scanning tools were detected. The active build setup compensates for much of this gap, making it a minor concern rather than a severe risk.
All 13 workflows were analyzed, but 119 of 120 action references are unpinned, and the audit found high-confidence template-injection findings plus a trusted-publishing concern. The pull_request_target workflows showed no untrusted checkout or script-injection sink, so these are workflow hygiene and release-process concerns rather than standalone evidence of an unsafe package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
babel-runtime Version ^6.22.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.