An alias package for `crypto.randomBytes` in Node.js and/or browsers
64%
Total Score
caution
Usable with caveats: no release or commit activity since March 2023.
No build attestation, trusted publisher, or staged publishing evidence was collected, leaving release provenance less transparent.
The package has only 3 releases and none in the last 12 months; its latest release was in March 2023, indicating a long maintenance gap. Its small, focused scope partly reduces the significance of infrequent releases.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the extended release gap and raising abandonment risk.
The repository has no security policy, which weakens the documented process for reporting and handling vulnerabilities.
The single workflow was fully audited with no dangerous triggers, untrusted checkouts, or script injection, but both action references are unpinned and it has a high-confidence adhoc-packages finding for installing outside a lockfile. These are workflow hygiene concerns rather than severe risks.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.