Import with sanity.
78%
Total Score
100
50
94
83
50
No build attestation or trusted-publisher provenance is recorded, leaving the artifact-to-source publishing path less transparent than it could be.
The package declares 19 runtime dependencies and 44 development dependencies, a moderately substantial profile for a linting plugin. This is manageable but increases maintenance surface.
The package has 136 releases since March 2015, but none in the last 12 months and the latest registry release was about 15 months ago. Active repository commits partly compensate, but the release gap remains a maintenance concern.
All 7 workflows were analyzed with no high- or medium-severity findings and no untrusted checkout or script-injection sinks. However, all 21 action references are unpinned, several jobs install packages outside a lockfile, and one workflow grants top-level write access, creating build-integrity hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^3.2.7 | — | — |
hasown Version ^2.0.2 | — | — |
semver Version ^6.3.1 | — | — |
is-glob Version ^4.0.3 | — | — |
doctrine Version ^2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.