SHA1 wrapper for browsers that prefers `window.crypto.subtle`.
68%
Total Score
caution
Usable with caveats: nearly three years without a registry release and no commits in the last three months weaken maintenance confidence.
No build attestation or trusted-publisher identity is recorded, leaving release origin less independently verifiable. This is a transparency gap, but not severe enough to outweigh the repository and organization evidence.
The package has eight releases over about five years, but its latest registry release was nearly three years ago and there were no releases in the last 12 months, which lowers maintenance confidence.
The repository recorded zero commits and zero active maintainers in the last three months. Although the repository was pushed recently, the measured commit activity indicates limited recent development.
There were no new or closed issues or merged pull requests in the last month, despite 25 open pull requests and 8 open issues, suggesting unresolved maintenance backlog.
All six workflows were analyzed with no untrusted checkout or script-injection findings, and most workflows use read-only permissions. However, all 10 action references are unpinned and a high-confidence audit found ad hoc package installation in the production release workflow, creating a supply-chain hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.6.2 | — | — |
@aws-sdk/types Version ^3.222.0 | — | — |
@aws-crypto/util Version ^5.2.0 | — | — |
@smithy/util-utf8 Version ^2.0.0 | — | — |
@aws-sdk/util-locate-window Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.