Creates a Promise that waits for a single event
78%
Total Score
healthy
Healthy release with recent publishing and provenance; workflow hygiene and a single-maintainer base are the main caveats.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is no provided project-backing evidence to offset the thin publishing base.
No commits or active maintainers were recorded in the last three months, which is a maintenance concern, although the latest release and repository push show recent publication activity.
The project uses TypeScript and npm scripts, but no security scanning tools were detected; this is a modest transparency and maintenance gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified; this is a minor transparency gap for a small package.
Both workflows were analyzed without trigger or untrusted-checkout sinks, and one scopes permissions read-only. However, all 7 action references are unpinned and the release workflow has a high-confidence low-severity adhoc-package finding.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-3449 @tootallnate/once is vulnerable to Incorrect Control Flow Scoping in versions 3.0.0 - 3.0.1 and 0.0.0 - 2.0.1. | 0.0.0 - 2.0.13.0.0 - 3.0.1 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.