ECMAScript extensions and shims
62%
Total Score
50
92
50
A postinstall script runs during installation, increasing build and supply-chain complexity. The provided release notes specifically document a recent postinstall regression, so this is a real operational concern rather than a cosmetic gap.
The package has 84 releases over more than 15 years, but none in the last two years. That long history supports maturity, while the recent release gap raises maintenance concerns.
The repository had zero commits and zero active maintainers in the last three months, consistent with the absent recent registry releases and indicating limited current maintenance.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented. This is a transparency gap, though it is partly offset by the repository's tests and established project documentation.
All three workflows were analyzed without dangerous triggers or audit findings, but all three action references are unpinned. That leaves routine workflow dependencies less reproducible than they could be.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-27088 es5-ext is vulnerable to Inefficient Regular Expression Complexity in versions 0.10.0 - 0.10.63. | 0.10.0 - 0.10.63 | Low |
| Dependency | Last Release | Score |
|---|---|---|
esniff Version ^2.0.1 | — | — |
next-tick Version ^1.1.0 | — | — |
es6-symbol Version ^3.1.3 | — | — |
es6-iterator Version ^2.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.