Is this value a JS WeakMap? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
67%
Total Score
75
100
94
67
50
No build attestation or trusted-publisher provenance is present, so consumers cannot independently verify how this release was published. The package's matching repository and simple structure provide some context but do not replace provenance.
The package uses prepack and prepublish lifecycle scripts. These are not necessarily unsafe, but they add build-time behavior that should be understood when reproducing or auditing the release.
The package has existed for about 11.6 years but has only five releases, with no release in the last 12 months and a latest release about 2.5 years ago. This is a meaningful maintenance concern for a dependency, despite the package's stable history.
There were no commits and no active maintainers in the last 3 months. This reinforces the slow registry release cadence, although the repository had a push about 8 months ago.
All five workflows were analyzed successfully with no audit findings and no untrusted checkouts or script injection. However, all five action references are unpinned, reducing build reproducibility and leaving action versions less controlled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.