The project has clear documentation, bundled typings, and a small dependency footprint. Workflow permissions and unpinned actions need tightening, while the missing security policy is a minor transparency gap.
88%
Total Score
83
100
94
67
100
One contributor made two-thirds of recent commits, but two additional contributors each made five commits, providing meaningful though limited backup.
The project uses TypeScript, npm scripts, and Rollup, but no security scanning tool was detected; this is a modest repository hygiene gap.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented.
All three workflows grant top-level write permissions and all six action references are unpinned. The audit found no untrusted checkout, injection, or other high-confidence dangerous workflow pattern, so this is a hygiene caution rather than a severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-646955 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. emnapi is vulnerable to Type Confusion in versions 0.31.0 - 1.11.2. | 0.31.0 - 1.11.2 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.