High performance (de)compression in an 8kB package
78%
Total Score
50
100
95
90
50
No build attestation, trusted publisher, or staged publishing evidence is available, leaving publication provenance less transparent despite the package's conventional contents.
Only one registry publishing account is listed, which creates some continuity risk; however, the linked repository is an active user-owned project with a matching package and documented releases.
No commits or active maintainers were recorded in the last three months. Recent releases and a repository push provide some compensation, but the lack of current commit activity is a meaningful maintenance concern.
The repository still receives issues and pull requests, but none were closed or merged in the last month, suggesting some backlog and limited recent response.
The project uses TypeScript, Parcel, and npm scripts for builds, but no security scanning tools were detected, leaving a modest security-process gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-45820 fflate is vulnerable to Uncontrolled Resource Consumption in versions 0.4.5 - 0.4.9, 0.5.0 - 0.5.4, 0.6.0 - 0.6.11, 0.7.0 - 0.7.5 and 0.8.0 - 0.8.3. | 0.4.5 - 0.4.90.5.0 - 0.5.40.6.0 - 0.6.11 +2 more | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.