The MIT license, bundled type declarations, focused dependency set, and usable README support adoption. A prepare script and missing build attestation leave provenance less transparent, while the limited release history warrants pinning this version.
66%
Total Score
100
92
75
50
No build attestation, trusted publisher, or staged publishing evidence is present, so the origin of the published artifact is less independently verifiable.
A prepare script runs during package lifecycle operations, adding build or install behavior that consumers should account for; no other lifecycle scripts are shown.
The package has only 2 releases across 463 days, with 1 release in the last 12 months and a median interval of about 236 days; this suggests limited demonstrated maintenance, though the latest release is recent.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-25547 @isaacs/brace-expansion is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 5.0.0. | 0.0.0 - 5.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
@isaacs/balanced-match Version ^4.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.