Next-gen browser and mobile automation test framework for Node.js
91%
Total Score
healthy
Long-running, actively maintained project with strong provenance; workflow credential and template hygiene need attention.
All 26 workflows were analyzed successfully; 37 of 38 action references are pinned, and job-level or read-only permissions are used in most workflows. High-confidence template-injection findings and secrets-inherit findings, plus one ad hoc package installation, are workflow hygiene concerns; the single pull_request_target workflow has no reported untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jszip Version ^3.10.1 | — | — |
htmlfy Version ^0.8.1 | — | — |
cheerio Version ^1.0.0-rc.12 | — | — |
rgb2hex Version 0.2.5 | — | — |
archiver Version ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.