Serverless CLI utilities
52%
Total Score
caution
Usable with caveats: no release in nearly three years raises maintenance risk.
No build attestation or trusted publisher provenance is present, so consumers cannot independently verify how the release artifact was produced. This is a publishing-transparency gap, not evidence of malicious behavior.
The package declares 33 runtime dependencies, including several CLI, networking, archive, and file-handling components. This increases update and transitive-maintenance burden, although the package's broad utility scope partly explains it.
The package has a substantial history with 102 releases, but its latest release was nearly three years ago and it had no releases in the last 12 months. That long pause is a meaningful maintenance concern despite its mature history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
d Version ^1.0.1 | — | — |
ms Version ^2.1.3 | — | — |
ext Version ^1.7.0 | — | — |
got Version ^11.8.6 | — | — |
log Version ^6.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.