This is a healthy, mature release with strong ongoing maintenance and release discipline: it has 232 releases over roughly 6.7 years, 36 releases in the last 12 months, a stable non-prerelease version, recent repository activity, 10 active contributors, organization backing, and build provenance attestation. The MIT license, bundled TypeScript declarations, minimal runtime dependency set, reproducible-looking package contents, and absence of install-time scripts further support safe adoption. There are modest transparency and repository-context concerns: the artifact omits tests and a changelog (though the repository contains both), the repository does not explicitly name or mention this subpackage, no security policy was found, and one workflow uses pull_request_target with incomplete top-level permission declarations. These issues warrant review of the repository and release workflow but do not outweigh the package's strong maintenance and provenance signals.
88%
Total Score
90
100
95
70
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@algolia/client-common Version 5.59.0 | — | — |
@algolia/requester-fetch Version 5.59.0 | — | — |
@algolia/requester-node-http Version 5.59.0 | — | — |
@algolia/requester-browser-xhr Version 5.59.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.