Package Health

@aws-crypto/sha1-browser

SHA1 wrapper for browsers that prefers `window.crypto.subtle`.

Latest 5.2.0NPMNPM

68%

Total Score

caution

Usable with caveats: nearly three years without a registry release and no commits in the last three months weaken maintenance confidence.

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity is recorded, leaving release origin less independently verifiable. This is a transparency gap, but not severe enough to outweigh the repository and organization evidence.

Release historycaution

The package has eight releases over about five years, but its latest registry release was nearly three years ago and there were no releases in the last 12 months, which lowers maintenance confidence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Although the repository was pushed recently, the measured commit activity indicates limited recent development.

Repo issue activitycaution

There were no new or closed issues or merged pull requests in the last month, despite 25 open pull requests and 8 open issues, suggesting unresolved maintenance backlog.

Workflow auditcaution

All six workflows were analyzed with no untrusted checkout or script-injection findings, and most workflows use read-only permissions. However, all 10 action references are unpinned and a high-confidence audit found ad hoc package installation in the production release workflow, creating a supply-chain hygiene caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.6.2
—
—
@aws-sdk/types
Version ^3.222.0
—
—
@aws-crypto/util
Version ^5.2.0
—
—
@smithy/util-utf8
Version ^2.0.0
—
—
@aws-sdk/util-locate-window
Version ^3.0.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
5 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform