Get and robustly cache all JS language-level intrinsics at first require time
68%
Total Score
50
50
100
75
50
No build attestation or trusted publisher identity is available, leaving the relationship between the published artifact and its source less independently verifiable.
Two of six workflows use pull_request_target, which warrants caution because that trigger can expose elevated workflow context to pull requests. No untrusted checkout or script injection was detected.
The package has 10 runtime dependencies for a small JavaScript utility, increasing dependency surface somewhat, but the dependencies are explicitly declared and appear purpose-specific.
The package uses prepack and prepublish lifecycle scripts, which add publishing and installation-adjacent complexity compared with a package containing no lifecycle scripts.
Only one registry account has publish access, creating a narrow publishing base. The matching source repository and recent activity partly offset the bus-factor concern, but do not remove it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gopd Version ^1.2.0 | — | — |
hasown Version ^2.0.2 | — | — |
es-errors Version ^1.3.0 | — | — |
get-proto Version ^1.0.1 | — | — |
has-symbols Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.