The source includes tests, a changelog, a license, security scanning, and organization backing. Its tiny public footprint and absent security policy provide less assurance, while workflow pinning still needs attention.
55%
Total Score
83
100
89
67
The package has 97 releases since March 2021, but none in the last two years since June 2024; that long release gap is a meaningful maintenance concern.
There were no commits and no active maintainers in the three months measured, which is consistent with the package's prolonged release gap and raises abandonment risk.
The repository has only 1 star and 1 fork, so there is little community adoption evidence; this is supporting concern rather than a verdict by itself.
The repository has no security policy, leaving disclosure and response expectations undocumented.
The single workflow is fully analyzed and uses read-only permissions, with no untrusted checkout or script-injection path. However, it has a high-confidence unpinned container image finding, weakening build reproducibility and provenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/anti-xss Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.