EditorConfig File Locator and Interpreter for Node.js
78%
Total Score
83
100
94
90
100
The repository recorded zero commits and zero active maintainers in the last three months. This is a real maintenance warning, although recent release activity and a push earlier in the year provide some compensating evidence.
The project uses CMake, TypeScript, and npm build tooling, but no security scanning tools were detected, leaving a modest transparency and security-hygiene gap.
Both workflows lack top-level token permissions, and one relies on job-level permissions only. This is less explicit than least-privilege declarations at workflow scope and creates a minor supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
semver Version ^7.7.4 | — | — |
commander Version ^14.0.3 | — | — |
minimatch Version ~10.2.4 | — | — |
@one-ini/wasm Version 0.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.