Cypress is a next generation front end testing tool built for the modern web
62%
Total Score
caution
Usable with caveats: high-confidence workflow findings affect supply-chain safety despite strong maintenance and project backing.
Two pull_request_target workflows perform untrusted checkouts, and high-confidence template-injection findings occur in one of those workflows; this creates a material supply-chain risk. Low-confidence github-env and cache findings are only hygiene concerns, while all 42 action references are pinned and the audit was complete.
No build attestation or trusted-publisher provenance is reported, leaving release origin less independently verifiable despite the active source project.
The package declares 39 runtime dependencies, a relatively broad profile for a full browser-testing tool, adding maintenance surface but fitting its substantial functionality.
A postinstall script is present. This is a mild supply-chain consideration for a tool that packages and prepares executable components, but the signal alone does not show unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tmp Version ~0.2.4 | — | — |
arch Version ^3.0.0 | — | — |
chalk Version ^4.1.0 | — | — |
dayjs Version ^1.11.23 | — | — |
debug Version ^4.3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.