Check if something is a Node.js stream
79%
Total Score
75
100
89
88
50
No build attestation or trusted-publisher provenance is present, leaving publication origin less verifiable than it could be. This is a transparency gap, not evidence that the release is unsafe.
The project is mature, with releases since 2015, but it has had no registry release in the last 12 months and its median release interval is about 449 days. That is a modest maintenance concern for a stable utility.
There were no commits from active maintainers in the last three months. Combined with the infrequent release history, this indicates quiet maintenance, although the package is small and stable.
The repository reports no build tool or security-scanning tool. For this small package that is a modest hygiene gap rather than a severe maturity concern.
The single workflow was fully analyzed with no reported audit findings or untrusted checkout and script-injection paths. Both of its two action references are unpinned, which is a minor reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.