core-js compat
82%
Total Score
75
100
95
88
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less independently verifiable than it could be.
Only one registry account has publish access. This is a real publishing continuity concern, although the linked repository shows active project work.
Five contributors were active in the last three months, but the leading contributor made 79 of 84 commits, or about 94%, creating substantial continuity risk.
The project uses Babel and npm scripts for builds, but no security scanning tools were detected, leaving a modest tooling gap.
All five workflows were analyzed with no untrusted checkouts, script injection, or audit findings. However, all 38 action references are unpinned and one workflow grants top-level write permissions, creating workflow reproducibility and least-privilege concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
browserslist Version ^4.28.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.