Parses data: URLs
72%
Total Score
caution
Usable with caveats: recent release activity offsets a quiet commit period, but all workflow actions are unpinned.
No commits or active maintainers were recorded in the last three months, which is a meaningful maintenance concern. The current release, today's repository push, and two merged pull requests partly offset that quiet period.
The repository reports no build tool and no security-scanning tool. For this compact package the lack of a build system is unsurprising, but the absence of security scanning is a modest hygiene gap.
No type declarations are shipped, which reduces convenience for TypeScript consumers of this library. This is a consumer-ergonomics gap rather than evidence of abandonment.
Both workflows were analyzed without failures and no untrusted checkout or script-injection paths were found. However, all 4 action references are unpinned and one workflow has top-level write permissions; the low-confidence cache-poisoning finding is hygiene only.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
whatwg-url Version ^17.1.2 | — | — |
whatwg-mimetype Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.