Get an iterator for any JS language value. Works robustly across all environments, all versions.
68%
Total Score
50
50
83
83
The package has nine runtime dependencies for a small compatibility library, including several focused utility packages. This adds some transitive maintenance surface but is not excessive enough to be a severe concern.
The repository is owned by a user account rather than an organization, so the single registry maintainer is not explained by organization backing. This leaves a relatively thin ownership base, though the repository itself is active enough to offset part of that concern.
The package has existed for about 6 years 10 months with seven releases, but it has had no release in the last 12 months and its latest release was in January 2023. The long history supports maturity, while the extended release gap lowers confidence in active maintenance.
There were no commits and no active maintainers in the last three months. Combined with the lack of recent registry releases, this indicates currently limited maintenance activity.
The repository uses Rollup, showing an established build process, but no security-scanning tooling was detected. The missing scanner is a hygiene gap, not proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
is-map Version ^2.0.2 | — | — |
is-set Version ^2.0.2 | — | — |
isarray Version ^2.0.5 | — | — |
call-bind Version ^1.0.2 | — | — |
is-string Version ^1.0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.