Sitecore JSS initializer
88%
Total Score
100
100
90
80
50
No build attestation, trusted publisher identity, or staged publishing is present, leaving the correspondence between source and published artifact less verifiable.
The repository uses TypeScript and npm build tooling, but no security scanning tools were detected; the build tooling is appropriate while the security-tooling gap modestly limits assurance.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.
All four workflows lack top-level permissions declarations. Although none declares top-level write permissions, explicitly constraining workflow tokens would provide stronger least-privilege assurance.
Version 23.0.0 is a stable major release and is not a prerelease. The recent prerelease share is high at 90%, which merits some caution around the broader release stream but does not undermine this stable release on its own.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10383 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. create-sitecore-jss is vulnerable to Use of Unmaintained Third-Party Components in versions 22.0.0 - 22.6.0. | 22.0.0 - 22.6.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
ejs Version ^3.1.10 | — | — |
diff Version ^8.0.2 | — | — |
glob Version ^13.0.6 | — | — |
chalk Version ^4.1.2 | — | — |
dotenv Version ^17.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.