Convert a JavaScript value to an estree expression
73%
Total Score
67
100
94
88
100
The repository is owned by an individual rather than an organization, so continuity depends on a single project owner; other release and repository evidence partly offsets this risk.
No commits or active maintainers were recorded in the last three months, despite a push in April 2026; this indicates a recent maintenance slowdown rather than clear abandonment.
The repository uses TypeScript and npm build tooling, but no security-scanning tool was detected; this is a minor transparency gap rather than a severe concern.
The workflow audit completed fully and found no untrusted checkout or script-injection path, with job-level permissions used. However, all 14 action references are unpinned, and the reported cache-poisoning findings are low-confidence hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-32014 estree-util-value-to-estree is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 3.3.3. | 0.0.0 - 3.3.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@types/estree Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.