Look up HTML tag names via HTML Element constructors, and vice versa.
78%
Total Score
healthy
Healthy: recent releases and ongoing repository maintenance support dependable adoption.
Staged publishing is enabled, but no build attestation is present. This leaves publication origin less independently verifiable than an attested release.
The package uses prepack and prepublish scripts, which are common for preparing published artifacts but add install and publication behavior that should be understood by adopters.
All five recent commits came from one contributor, leaving maintenance dependent on a single person. The repository is user-owned, so no organizational handoff evidence compensates for that concentration.
The package has no type declarations, which reduces convenience for typed consumers of this JavaScript library but does not indicate abandonment or a supply-chain transparency problem.
All six workflows were analyzed with no audit findings, and five use read-only permissions. However, all six action references are unpinned and one workflow has top-level write permissions, creating a moderate workflow-hygiene concern without an observed untrusted sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
es-errors Version ^1.3.0 | — | — |
array.prototype.filter Version ^1.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.