Identify legacy polyfills and code transforms
64%
Total Score
caution
A tiny package points to a different project, with slow releases and weak workflow pinning.
No build attestation or trusted-publisher configuration is present, leaving the artifact's build origin less transparent than it could be.
The package has only 3 releases across 559 days, with a median interval of about 280 days. The latest release is current, but the sparse cadence limits maturity evidence.
The repository name does not match the package name and its README does not mention this package, so the artifact's relationship to the source project is unclear. Monorepo packaging can explain a name mismatch, but the absent README mention remains a transparency gap.
The repository has no published security policy, reducing transparency about vulnerability reporting and response expectations.
Version 0.0.3 is not a prerelease, but it remains below 1.0, which signals a relatively immature compatibility commitment.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.