Recursively assign default properties. Lightweight and Fast!
82%
Total Score
83
100
94
80
No commits or active maintainers were recorded in the last three months. This is a meaningful maintenance concern, though it is partly offset by the recent release and repository push activity.
The repository uses TypeScript and a build tool, but no security scanning tools were detected. This is a modest transparency and supply-chain hygiene gap.
No repository security policy was found, leaving vulnerability-reporting guidance unclear. The gap lowers transparency but is not by itself evidence that the package is unsafe.
The only workflow lacks top-level token permissions. No write permissions were detected, but explicitly restricting permissions would provide stronger workflow hardening.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-35209 defu is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 6.1.4. | 0.0.0 - 6.1.4 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.