Package Health

entities

entities 8.1.0 appears to be a healthy dependency: it has a long release history, a current stable major release, recent releases, no registry deprecation, active repository maintenance, three active contributors in the last three months, tests in the repository, build and security tooling, a security policy, and npm provenance attestation. The package is transparently linked to a matching repository, has an explicit BSD-2-Clause license, bundled type declarations, no runtime dependencies, and no install-time lifecycle scripts. The main reservations are that recent commits are concentrated in one contributor and one workflow uses pull_request_target with write permissions, while the publish workflow lacks top-level permissions; these warrant normal supply-chain review but do not outweigh the strong maintenance and provenance evidence.

Latest 8.1.0NPMNPM

92%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 days ago
Created
14 years ago
Unpacked Size
0.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform