Trigger functions and/or evaluate cron expressions in JavaScript. No dependencies. Most features. All environments.
78%
Total Score
63
100
90
50
No build attestation or trusted-publisher provenance is available, reducing publication transparency, though this is not by itself evidence that the package is unsafe.
Only one registry publishing account is listed, creating some continuity risk, although the linked repository shows an established project and recent release activity.
The repository is owned by an individual user rather than an organization, so the single registry maintainer represents a genuine continuity risk rather than normal organization publishing hygiene.
No commits and no active maintainers were recorded over the last three months, which is a meaningful maintenance concern. Recent releases and pull-request merges partly compensate, but the lack of direct commit activity should be monitored.
Five workflows lack top-level permission declarations and one workflow grants top-level write access, which weakens least-privilege clarity in CI configuration.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.