Use react-devtools outside of the browser
84%
Total Score
100
100
94
80
50
No build attestation, trusted publisher identity, or staged publishing is recorded, leaving release provenance less verifiable than it could be.
Four workflows use pull_request_target and two use workflow_run, which warrants workflow review, but there are no untrusted checkouts or detected script-injection patterns to elevate this to a severe concern.
A prepublish lifecycle script is present, adding some release-process complexity, but this signal alone does not establish a maintenance or dependency-safety failure.
The linked repository name does not match react-devtools-core and its README does not mention the package. Although a monorepo can legitimately contain subpackages, this lack of an explicit package reference makes the source relationship harder to verify.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-5654 react-devtools-core is vulnerable to Improper Encoding or Escaping of Output in versions 0.0.0 - 4.28.4. | 0.0.0 - 4.28.4 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ws Version ^7 | — | — |
shell-quote Version ^1.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.