This release appears to be a healthy dependency: it is actively and frequently released, backed by an organization-owned repository with recent pushes, substantial recent commit activity, 20 active contributors, automated build and dependency tooling, and npm provenance attestation. The package is licensed, typed, documented, free of install-time lifecycle scripts, not deprecated or archived, and its repository contains tests even though tests are not included in the artifact. The main weaknesses are the absence of a security policy and incomplete top-level GitHub Actions permission declarations, which reduce repository security transparency but do not outweigh the strong maintenance and provenance evidence.
88%
Total Score
100
100
100
67
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
uuid Version ^13.0.2 | — | — |
axios Version ^1.18.1 | — | — |
partysocket Version ^0.0.23 | — | — |
socket.io-client Version ^4.8.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.