like `chown -R`
65%
Total Score
50
100
89
67
A prepare script runs during installation, adding build-time behavior, but this signal alone does not show that the script is unsafe or unusually complex.
The repository is owned by an individual account rather than an organization, so the project has less visible institutional backing and depends on a narrow maintainer base.
The package has 11 releases and its latest release was in April 2024, with no releases in the last 12 months; this indicates slowed release maintenance.
There were no commits or active maintainers in the last 3 months, which is a meaningful maintenance warning, although the repository was pushed in November 2025.
Only one issue and two pull requests are open, with no new or closed activity in the last month; this is quiet but not by itself evidence of abandonment.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-18869 chownr is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 1.1.0. | 0.0.0 - 1.1.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.