Zero-dependency cooperative LIFO execution for Node.js and browsers
84%
Total Score
83
100
100
75
The repository is owned by an individual account rather than an organization, so the small maintainer base has less institutional backing to absorb a handoff.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is not evidence of unsafe code by itself.
All 20 analyzed action references are pinned, but the pages workflow combines a workflow_run trigger with an untrusted checkout, and two workflows grant top-level write permissions. The audit also found high-confidence low-severity ad hoc package installs in CI and publishing workflows, so workflow hygiene warrants caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.