entities 8.1.0 appears to be a healthy dependency: it has a long release history, a current stable major release, recent releases, no registry deprecation, active repository maintenance, three active contributors in the last three months, tests in the repository, build and security tooling, a security policy, and npm provenance attestation. The package is transparently linked to a matching repository, has an explicit BSD-2-Clause license, bundled type declarations, no runtime dependencies, and no install-time lifecycle scripts. The main reservations are that recent commits are concentrated in one contributor and one workflow uses pull_request_target with write permissions, while the publish workflow lacks top-level permissions; these warrant normal supply-chain review but do not outweigh the strong maintenance and provenance evidence.
92%
Total Score
70
100
100
80
100
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.