The modern build of lodash’s internal `baseCopy` as a module.
62%
Total Score
100
88
83
The package has had only two releases, with the latest published in April 2015 and none in the last 12 months. Active work in the linked repository partly offsets the age, but does not show that this release is still refreshed.
The linked lodash repository neither matches the package name nor mentions lodash._basecopy in its README. This may be normal for a monorepo sub-package, but the lack of an explicit package reference weakens provenance transparency.
All 8 workflows were analyzed with no untrusted checkouts, script injection, high-severity findings, or unpinned action references. Three high-confidence low-severity adhoc-package findings are minor workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.