78%
Total Score
healthy
Healthy release, supported by active maintenance and an unarchived project despite workflow and package-linkage concerns.
The release has no build attestation or trusted-publisher provenance, so consumers have less independent evidence connecting the published artifact to its source build.
Twelve runtime dependencies create a meaningful transitive maintenance surface for a utility package, though the profile is not unusually large enough to indicate severe risk.
The repository name does not match the package name and its README does not mention this package. Although a name mismatch can be normal for a monorepo, the absence of both signals creates uncertainty that this repository is the package's intended source.
The project uses TypeScript, npm scripts, and SWC for builds, but the collected repository tooling includes no security-scanning tools. That is a modest transparency and hygiene gap, not evidence of abandonment.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ajv Version ^8.18.0 | — | — |
tslib Version ^2.8.1 | — | — |
lodash Version ^4.18.1 | — | — |
ajv-errors Version ~3.0.0 | — | — |
ajv-formats Version ~2.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.