ECMAScript 5 compatibility shims for legacy JavaScript engines
68%
Total Score
50
100
93
75
50
The release has no build attestation or staged-publishing evidence, leaving publication provenance less transparent. This is partly offset by the package's established history and linked source repository, but it remains a modest supply-chain hygiene gap.
The package has 95 releases over more than 15 years, but its latest registry release was in May 2022 and it had no releases in the last 12 months. That long release gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although the repository is not archived, the current lack of observed development is a maintenance concern.
All five analyzed workflows use unpinned action references, reducing build reproducibility and increasing exposure to upstream action changes. The pull_request_target workflows have no untrusted checkouts or script-injection findings, so this is a hygiene caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.