Sourcemap support for gulpjs.
78%
Total Score
100
50
83
100
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less independently verifiable.
Eleven runtime dependencies create some dependency-chain maintenance exposure for a small utility package, but the profile is not extreme on its own.
The package has 72 releases over roughly 12 years, but no registry release in the last 12 months and its latest release was in November 2020. This is a meaningful freshness concern, partly offset by recent repository activity.
The project uses a build tool, but no security-scanning tooling was detected. The missing scanner is a hygiene gap rather than evidence of unsafe maintenance.
No type declarations are published, which is a minor integration gap for TypeScript consumers but not a maintenance or abandonment concern by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
css Version ^3.0.0 | — | — |
acorn Version ^6.4.1 | — | — |
through2 Version ^2.0.0 | — | — |
source-map Version ^0.6.0 | — | — |
graceful-fs Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.