82%
Total Score
88
94
100
50
No build attestation or trusted-publisher provenance was reported, so consumers have less independently verifiable evidence connecting the published artifact to its source build.
Recent activity is highly concentrated: one contributor made about 96% of commits, while the other two made only three commits combined. Organization backing partly offsets the handoff risk, but the concentration remains a caution.
The project uses established build tooling, but no security-scanning tools were detected. That is a modest maintenance and detection gap rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
chalk Version ^4.1.2 | — | — |
expect Version 30.5.2 | — | — |
semver Version ^7.7.2 | — | — |
synckit Version ^0.11.8 | — | — |
jest-diff Version 30.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.