Package Health

@foliojs-fork/fontkit

An advanced font engine for Node and the browser

Latest 1.9.2NPMNPM

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Name lookalikedanger

The package identifies itself as a fork of fontkit, but its 0.95 artifact overlap, borrowed identity, and lookalike README strongly indicate consumers may have intended the established fontkit package instead.

Release historycaution

The package has only 3 releases since July 2021, with no releases in the last 12 months and a median interval of about 490 days, indicating a slow maintenance cadence.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, which provides little evidence of ongoing maintenance.

Repo popularitycaution

The linked repository has only 2 stars, 3 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these low figures provide little additional confidence in project maturity.

Repo toolingcaution

The repository uses Rollup and Babel for builds, showing an established build process, but it has no detected security-scanning tools.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
dfa
Version ^1.2.0
—
—
clone
Version ^1.0.4
—
—
brotli
Version ^1.2.0
—
—
deep-equal
Version ^1.0.0
—
—
tiny-inflate
Version ^1.0.2
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
5 years ago
Unpacked Size
3.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform