JS library for Fengari
72%
Total Score
75
88
67
The package is mature at about 9 years old, but it has only 6 releases and a median interval of about 10.5 months; just 1 release arrived in the last 12 months. This suggests deliberate but relatively slow maintenance.
There were 0 commits and 0 active maintainers in the last 3 months. The recent release and non-archived repository partly compensate, but the lack of current development is a real maintenance concern.
No repository security policy was found. This is a transparency and disclosure gap, but it is not by itself evidence that the package is unsafe to depend on.
Version 0.1.4 is not a prerelease, and recent releases are not marked prerelease, but the pre-1.0 major version indicates API stability may still be limited.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or high-severity issues. However, both of its 2 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.