A simple binding to Google's cpu_features library for obtaining information about installed CPU(s)
58%
Total Score
50
81
50
50
No build attestation, trusted publisher, or staged publishing is reported, reducing release transparency. This is a provenance gap, not evidence that the release is unsafe by itself.
An install script is present, which adds execution during installation and therefore some supply-chain exposure. For a native Node.js binding that must build through node-gyp, this is expected package behavior rather than an inherently severe issue.
Only one registry account has publish access, leaving a thin publishing base. The linked repository is also owned by an individual, so there is no organizational backing shown to compensate for that concentration.
The package has had no releases in the last 12 months, with the latest release in May 2024 despite a history dating to 2019. This is a meaningful maintenance concern, though the repository remains available and was pushed more recently.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the long gap since the latest registry release, this raises abandonment risk despite the later repository push timestamp.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nan Version ^2.19.0 | — | — |
buildcheck Version ~0.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.