Recursive object extending
58%
Total Score
25
100
80
75
50
The package has 21 releases, but its latest release was about 8 years ago and it has had no releases in the last 12 months. This is strong evidence of slowed maintenance, though the long release history suggests prior maturity.
The repository recorded no commits and no active maintainers in the measured three-month period. This reinforces the substantial age of the latest registry release and raises abandonment risk.
The release has no build provenance attestation or trusted-publisher metadata. This weakens publication transparency, although the package is a small, dependency-free artifact.
There were no new or closed issues or pull requests in the measured month, while 10 issues and 3 pull requests remain open. The lack of recent activity is consistent with a dormant project.
The linked repository has no security policy. This leaves vulnerability reporting and maintainer response expectations undocumented, a modest transparency gap for a dependency.
| Title | Versions | Severity |
|---|---|---|
CVE-2018-3750 deep-extend is vulnerable to Improper Input Validation in versions 0.0.0 - 0.5.1. | 0.0.0 - 0.5.1 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.