Scripts that autolink Expo modules.
86%
Total Score
healthy
Active releases and broad Expo maintenance outweigh workflow-audit gaps and publisher-account hygiene concerns.
The package has 13 publishing accounts and is backed by the Expo organization, but several accounts use consumer or outside domains, including gmail.com accounts and ide, bycedric, tsapeta, and philpl; this is an account-hygiene concern rather than evidence of weak maintenance capacity.
All 136 analyzed action references are pinned and no untrusted checkout or script-injection sink was found, but only 30 of 54 workflows were analyzed. High-confidence template-injection findings and six workflows with top-level write permissions warrant workflow-hygiene caution, although the flagged template-injection paths do not overlap the two pull_request_target workflows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chalk Version ^4.1.0 | — | — |
commander Version ^7.2.0 | — | — |
@expo/spawn-async Version ^1.8.0 | — | — |
@expo/require-utils Version ^57.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.