copy some files
55%
Total Score
38
50
81
75
50
The package has 18 releases but none in the last 12 months; its latest registry release was in November 2020. This is a significant maintenance and abandonment concern.
There were zero commits and zero active maintainers in the last three months. Together with the old registry release, this indicates sharply limited current maintenance.
No build attestation or trusted-publisher identity is present, leaving publication provenance less transparent. This is a supply-chain hygiene gap rather than evidence that the release is unsafe.
Seven runtime dependencies are a moderate footprint for a small CLI utility and add some maintenance surface, but the count alone does not indicate a serious problem.
Only one registry account has publish access. That is a thin publishing base and increases continuity risk, although repository activity is the stronger evidence of maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
glob Version ^7.0.5 | — | — |
noms Version 0.0.0 | — | — |
yargs Version ^16.1.0 | — | — |
mkdirp Version ^1.0.4 | — | — |
through2 Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.