This release appears to be a healthy dependency: it has a long and active release history, stable versioning, current repository activity, six active contributors, organizational backing, build provenance, licensing, type declarations, repository tests, changelog coverage, and security tooling. The package is not deprecated or archived, and the linked monorepo explicitly mentions it. The main caution is workflow permission hygiene: all seven analyzed workflows lack top-level permissions declarations, although none declares top-level write access and no untrusted checkout or script-injection issue was detected. Install-time postpack and prepack scripts also warrant normal review, but they are packaging scripts rather than evidence of abandonment.
91%
Total Score
100
50
100
70
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramda Version ~0.30.0 | — | — |
@types/ramda Version ~0.30.0 | — | — |
ramda-adjunct Version ^5.0.0 | — | — |
@babel/runtime-corejs3 Version ^7.26.10 | — | — |
@swagger-api/apidom-core Version ^1.12.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.