Find and load configuration from a package.json property, rc file, TypeScript module, and more!
88%
Total Score
100
100
94
63
A prepare install-time script adds some installation complexity and execution surface, though this is a common publishing workflow and no harmful behavior is shown.
The project uses TypeScript, Vite, and npm build tooling, but no security-scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear for a widely used library.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. However, all three action references are unpinned, creating a minor reproducibility and workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
js-yaml Version ^5.4.1 | — | — |
env-paths Version ^2.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.