Get the dependency tree of a module
82%
Total Score
67
100
100
67
One contributor made all recent commits, concentrating current maintenance on a single person; organization ownership provides some ability to hand off maintenance but does not remove the present concentration.
Only 2 commits were recorded in the last 3 months, so recent development activity is modest despite the recent release.
No repository security policy was found, leaving vulnerability-reporting expectations less transparent for consumers.
All three workflows use read-only permissions and the audit found no high- or medium-severity issues, but all 7 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
precinct Version ^13.0.0 | — | — |
commander Version ^14.0.3 | — | — |
typescript Version ^6.0.3 | — | — |
filing-cabinet Version ^6.0.0 | — | — |
@discoveryjs/json-ext Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.