84%
Total Score
88
100
95
80
50
No registry build attestation or trusted-publisher identity is present, reducing publication transparency, although this is not evidence of a maintenance failure by itself.
One workflow uses pull_request_target with an untrusted checkout, creating a meaningful CI exposure even though no script-injection workflows were detected.
The repository continues to receive issues and pull requests, though none of seven new pull requests were merged in the measured month and the backlog is large.
The repository uses established build tools, but no security-scanning tools were detected, leaving a modest security-process gap.
All 30 analyzed workflows lack top-level token permissions, and none declare read-only permissions; although no workflow has top-level write access, least-privilege configuration is not consistently explicit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.4.0 | — | — |
@yarnpkg/fslib Version ^3.1.3 | — | — |
@types/emscripten Version ^1.39.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.