Queue for messages and jobs based on Redis
88%
Total Score
healthy
Active maintenance and a real release trail outweigh workflow pinning and missing security policy.
A prepare lifecycle script runs during installation, adding build-time behavior that adopters should understand, although this signal alone is not evidence of an unhealthy project.
No SECURITY.md policy was found, leaving vulnerability reporting expectations unclear and creating a modest transparency gap despite the repository's security scanning tools.
All 12 workflows were analyzed with no untrusted checkouts or script injection, but two high-confidence findings use floating latest container images and one workflow installs outside a lockfile; 25 of 93 action references are unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version 2.8.1 | — | — |
semver Version 7.8.5 | — | — |
msgpackr Version 2.1.0 | — | — |
cron-parser Version 5.10.1 | — | — |
node-abort-controller Version 3.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.