A lightweight carousel library with fluid motion and great swipe precision
78%
Total Score
100
100
89
67
50
No build attestation or trusted-publisher provenance was reported, leaving the release origin less independently verifiable. This is a transparency gap, not evidence that the package is unsafe.
The repository name does not match this package and its README does not mention the package, creating some uncertainty about package-to-source ownership. The package README and monorepo-style file tree partly compensate for the mismatch.
The repository uses established build tooling including Rollup and TypeScript. No security-scanning tooling was detected, leaving a modest process gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
The audit found a high-confidence template-injection finding and a low-confidence cache-poisoning finding in the release workflow; because no untrusted checkout or relevant trigger was observed, these are workflow hygiene concerns rather than standalone severe risks. All four action references are unpinned, and one workflow grants top-level write access, adding further maintenance risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
embla-carousel Version 8.6.0 | — | — |
embla-carousel-reactive-utils Version 8.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.