Provides an interface for getting and setting Clipboard content on Android, iOS, macOS and Web.
91%
Total Score
100
100
94
88
50
The release has no build attestation or trusted-publisher identity, leaving publication provenance less independently verifiable despite the package's active project backing.
The linked repository name does not match expo-clipboard and its README does not mention the package, so the package-to-repository relationship is less transparent than ideal. The organization-owned monorepo context partly explains the name mismatch but does not remove the documentation gap.
Many analyzed workflows lack top-level permission declarations and six declare top-level write access, which is a workflow-hygiene concern; the absence of observed injection or untrusted-checkout patterns reduces its impact on package health.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10372 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. expo-clipboard is vulnerable to Relative Path Traversal in versions 0.0.1 - 4.8.0. | 0.0.1 - 4.8.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.