Yet another Base64 transcoder in pure-JS
88%
Total Score
75
100
95
83
50
No build attestation or trusted-publisher provenance is present, so consumers cannot independently verify how the registry artifact was produced; the package's otherwise transparent repository and simple dependency profile partly reduce the concern.
The repository is owned by an individual rather than an organization, so the concentrated recent commit share represents a genuine bus-factor consideration.
Four contributors were active, but the leading contributor made about 82% of recent commits, leaving maintenance somewhat concentrated.
The project uses build tooling including TypeScript, Rollup, Make, and npm scripts, but no security-scanning tools were detected; this is a minor hygiene limitation rather than a severe health concern.
Both workflows were analyzed without high- or medium-confidence findings, and permissions are not broadly writable; however, all five action references are unpinned, leaving avoidable maintenance and supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.