get a list of identifiers that are initialised by a JavaScript AST node.
62%
Total Score
50
100
89
80
50
No build attestation or trusted-publisher provenance is present, so publication cannot be independently tied to a verified build; this is a transparency gap, not evidence of maliciousness.
A single registry publisher is consistent with the repository being owned by one user; registry access alone does not establish maintenance capacity, so the commit evidence carries more weight.
The package has only three releases and none in the last 12 months; its latest registry release was on February 8, 2018, indicating a long-standing release freeze.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance and abandonment concern for a dependency.
There are no open issues or pull requests, and no recent issue or pull-request activity; this is neutral for a small stable utility but provides little evidence of active support.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.