Type declarations, release notes, and a large active contributor base add useful confidence. The workflow audit still warrants caution because publishing workflows contain high-confidence token-scope and template-injection findings, alongside many unpinned actions.
82%
Total Score
100
100
100
88
100
All 20 workflows were analyzed, but high-confidence findings include blanket GitHub App token permissions and template injection in release or publishing workflows; 77 of 94 action references are also unpinned. No untrusted checkout or pull_request_target path was reported, limiting the impact to a meaningful caution rather than a severe verdict.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-714632 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. nango is vulnerable to Observable Response Discrepancy in versions 0.16.0 - 0.70.7. | 0.16.0 - 0.70.7 | Low |
| Dependency | Last Release | Score |
|---|---|---|
ajv Version 8.18.0 | — | — |
ejs Version 3.1.10 | — | — |
ora Version 9.2.0 | — | — |
zod Version 4.3.6 | — | — |
conf Version 12.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.