This release appears to be a healthy dependency: it is actively maintained in a non-archived organization-owned repository, has substantial recent commit and pull-request activity, reproducible npm provenance, source and type declarations, licensing, security tooling, and no install-time lifecycle scripts. The main residual concerns are concentration of commits in one contributor and some GitHub Actions workflows with broad or incompletely declared permissions, but these are mitigated by 14 active contributors, organization backing, code scanning, and strong repository activity. The package is not deprecated and the artifact is well aligned with the repository, so it is a reasonable package to depend on.
91%
Total Score
88
50
100
80
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@solana/errors Version 8.3.0 | — | — |
@solana/promises Version 8.3.0 | — | — |
@solana/rpc-types Version 8.3.0 | — | — |
@solana/functional Version 8.3.0 | — | — |
@solana/subscribable Version 8.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.