A Twilio helper library
91%
Total Score
healthy
Healthy release backed by frequent maintenance, organization ownership, and npm provenance attestation.
A prepublish lifecycle script is present. This adds a small publication-process risk, but the package also has npm provenance and a long, active release history that provide useful compensation.
No repository security policy was found. That is a transparency gap for a client library handling authentication, though active maintenance and security scanning partly compensate.
The audit analyzed five of six workflows and failed on one, so coverage is incomplete. Three of 20 action references are unpinned and the auditor reported low-confidence cache-poisoning findings; there were no untrusted checkouts or script injections, limiting the impact to caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
qs Version ^6.14.1 | — | — |
scmp Version ^2.1.0 | — | — |
axios Version ^1.13.5 | — | — |
dayjs Version ^1.11.9 | — | — |
xmlbuilder Version ^13.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.