Package Health

es-module-lexer

Lexes ES modules returning their import/export metadata

Latest 3.0.3NPMNPM

88%

Total Score

healthy

Healthy: frequent releases and active repository work support dependable maintenance.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

The release has no build attestation or trusted-publisher provenance, leaving publication origin less independently verifiable despite the otherwise active project.

Project backingcaution

The repository is owned by an individual rather than an organization, so the concentrated contributor activity and single registry publisher are not supported by organizational handoff capacity.

Repo bus factorcaution

The top contributor made about 65% of recent commits, but a second contributor made about 26% and three others contributed, making this a moderate rather than severe concentration risk.

Repo toolingcaution

The repository uses build tooling, including Babel, SWC, TypeScript, and npm scripts, but reports no security-scanning tools, leaving a modest verification gap.

Security policycaution

The repository has no security policy, so vulnerability reporting and response expectations are not documented.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-875097 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
es-module-lexer is vulnerable to Out-of-bounds Write in versions 0.3.0 - 2.3.2.
0.3.0 - 2.3.2
Low

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 days ago
Created
7 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform