JavaScript Standard Style - ESLint Shareable Config
62%
Total Score
75
100
94
90
50
No build attestation or trusted-publisher provenance is available. This lowers publication transparency somewhat, but it is a supply-chain transparency gap rather than evidence that the package is unsafe or unfit on its own.
The package has a long history and 83 releases, but its latest registry release was about three years and four months before collection, with no releases in the last 12 months. That materially raises freshness and maintenance concerns despite the historically regular release cadence.
The repository recorded zero commits and zero active maintainers in the last three months. Although the recent push timestamp is reassuring, the observed short-term activity is still a maintenance concern.
There are 12 open issues and 17 open pull requests, showing an active backlog, but no issues or pull requests were created or closed in the last month. This is consistent with the broader caution about current maintenance pace.
Neither workflow declares top-level token permissions. While this is less explicit than a read-only declaration, no workflow has top-level write permissions, so the concern is limited.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.