
82%
Total Score
90
100
94
88
50
The release has no attestation and does not use staged publishing, leaving the registry artifact's build origin less verifiable. This is a transparency gap, partly offset by the visible repository and matching package structure.
The package uses prepack and prepare lifecycle scripts, which can execute during installation or packaging and add build-time complexity. Their names are consistent with normal source preparation, so this is a limited concern rather than a severe risk.
The repository has two new issues and no issues closed in the last month, although three pull requests were merged. This suggests some unresolved maintenance backlog but not clear abandonment.
The project uses TypeScript and Vitest and has build tooling, but no security-scanning tools were detected. The missing scanning reduces maintenance and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ora Version ^8.1.0 | — | — |
jszip Version ^3.10.1 | — | — |
semver Version ^7.6.2 | — | — |
http-proxy-agent Version ^7.0.2 | — | — |
https-proxy-agent Version ^7.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.