This release appears to be a healthy dependency: it has a clear MIT license, TypeScript declarations, substantial packaged output, repository-backed tests and changelog, frequent recent releases, active multi-contributor development, npm provenance, and no deprecation or archival indicators. The main reservations are that it remains below major version 1.0 with a high recent prerelease share, lacks repository security-scanning tooling and a security policy, and has incomplete GitHub Actions permission declarations; these are meaningful hygiene gaps but are outweighed by the strong maintenance and build-transparency evidence.
88%
Total Score
100
100
89
80
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
debug Version 4.4.3 | — | — |
json5 Version ^2.2.3 | — | — |
constant-case Version ^3.0.4 | — | — |
lodash.sortby Version ^4.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.