Fetch API implementation for Node
84%
Total Score
healthy
Healthy, with frequent releases and active repository work; unpinned workflow images are the main caveat.
Four contributors were active in three months, but one contributor made about 84% of commits. That concentration creates some continuity risk because the repository owner is an individual.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.
Version 0.9.1 is not a stable major release, and 95% of recent releases are prereleases, which increases compatibility uncertainty for dependents.
All five workflows were analyzed, with no untrusted checkout or script-injection paths. However, four high-confidence findings identify unpinned container images, leaving build inputs less reproducible and requiring workflow hygiene improvements.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.6.3 | — | — |
@fastify/busboy Version ^3.1.1 | — | — |
@whatwg-node/disposablestack Version ^0.1.0 | — | — |
@whatwg-node/promise-helpers Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.