Google API Extensions
87%
Total Score
healthy
Active Google-backed project with frequent releases and broad contributor activity; repository/package linkage is the main transparency concern.
No build attestation or trusted-publisher identity is present, reducing publication transparency, although the package has a long release history and active repository maintenance to compensate.
The package has a prepare install lifecycle script, which adds execution during installation and modestly increases dependency-installation risk.
Two of three publish-access accounts use the google.com domain, consistent with organization backing. The outside-domain account mrdoob (mrdoob.com) is an account-hygiene caution, not evidence of limited maintenance capacity.
The repository name does not match google-gax and its README does not mention the package, so the package-to-repository mapping is less transparent. The mismatch may reflect a monorepo, but the collected evidence does not confirm that.
All 71 analyzed action references are pinned and 17 workflows use read-only permissions, with no untrusted checkout or script-injection findings. The audit missed one of 19 workflows and found two high-confidence low-severity adhoc package installations, so workflow hygiene is not fully clean.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
duplexify Version ^4.1.3 | — | — |
node-fetch Version ^3.3.2 | — | — |
protobufjs Version ^7.5.4 | — | — |
object-hash Version ^3.0.0 | — | — |
@grpc/grpc-js Version ^1.12.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.