Convert CommonJS modules to ES2015
70%
Total Score
67
95
67
100
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the release history shows continued publishing.
Only one issue was opened and no issues or pull requests were closed or merged in the last month, suggesting limited recent repository activity alongside the commit gap.
The repository uses Rollup and TypeScript build tooling, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than a standalone severe risk.
No repository security policy was found, reducing transparency for vulnerability reporting and response expectations.
All 12 action references are unpinned and one workflow has top-level write permissions, creating workflow-hygiene concerns. High-confidence template-injection findings are present, but without untrusted triggers or checkout sinks they remain hygiene issues rather than standalone severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fdir Version ^6.2.0 | — | — |
commondir Version ^1.0.1 | — | — |
picomatch Version ^4.0.2 | — | — |
is-reference Version 1.2.1 | — | — |
magic-string Version ^0.30.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.