88%
Total Score
88
100
95
80
100
One contributor made about 89% of the recent commits, creating a real concentration risk. However, five other contributors were active during the same period and the repository is organization-owned, which partly compensates for the concentration.
The repository name does not match electron-publish and its README does not mention the package, so the package-to-repository relationship is less explicit. The package description identifies it as part of electron-builder, which makes a monorepo relationship plausible but does not fully remove the transparency gap.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent. This is a documentation gap, not evidence of abandonment.
Six workflows declare read-only permissions, but one lacks top-level permissions and two declare top-level write access. The mixed permissions posture warrants caution even though the workflow risk scan found no dangerous patterns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws4 Version ^1.13.2 | — | — |
mime Version ^2.5.2 | — | — |
chalk Version ^4.1.2 | — | — |
fs-extra Version ^10.1.0 | — | — |
lazy-val Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.