Standard library
82%
Total Score
75
93
67
A postinstall script adds execution during installation and deserves review because it increases the package's install-time behavior beyond ordinary file delivery.
Five contributors were active, but the primary contributor made about 94% of the 84 recent commits, leaving maintenance capacity highly concentrated.
The project uses Babel and npm build tooling, but no security scanning tools were detected; this is a modest transparency and hygiene gap, not evidence of abandonment.
All five workflows were analyzed with no detected injection or high-severity findings, but all 38 action references are unpinned and one workflow grants top-level write access, creating reproducibility and permissions concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.