64%
Total Score
50
100
88
67
50
There were no commits and no active maintainers in the past three months, a significant warning about current maintenance capacity.
No build attestation or trusted-publisher provenance is available, reducing release transparency, although this is not by itself evidence of an unsafe release.
The package is mature, with 241 releases over more than eight years, but only one release in the past 12 months indicates a substantially slower recent cadence.
Recent activity is limited: one new issue, no closed issues, two new pull requests, and no merged pull requests in the past month, suggesting slow issue resolution.
The repository uses TypeScript, Turbo, and npm scripts, but reports no security-scanning tools, leaving a notable transparency and maintenance-control gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mime Version 3 | — | — |
file-type Version ^21.3.3 | — | — |
@jimp/types Version 1.6.1 | — | — |
@jimp/utils Version 1.6.1 | — | — |
await-to-js Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.