The modern build of lodash’s `_.isObject` as a module.
68%
Total Score
100
88
83
The package has had no release in more than 11 years, despite 10 releases historically; this is a meaningful freshness and abandonment concern for the specific release.
The repository name does not match lodash.isobject and its README does not mention the package, so the exact package-to-repository relationship is less transparent; the organization-backed monorepo context partly explains the mismatch.
All 8 workflows were analyzed with no untrusted checkouts, script injection, or unpinned actions. Three high-confidence low-severity findings install packages outside a lockfile, a limited workflow hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.