Package Health

madge

Create graphs from module dependencies.

Latest 8.0.0NPMNPM

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The package has 77 releases since May 2012, but none in the last 12 months and the latest release was in August 2024. Its long history helps, but the recent release gap lowers confidence in ongoing maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful sign of currently limited development activity, despite the repository being recently pushed according to its archive-status signal.

Security policycaution

The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is less significant than the maintenance signals and does not by itself make the release unfit.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but both action references are unpinned and it installs a package outside a lockfile. The low-severity high-confidence finding is a build-hygiene caution, not a severe risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2021-23352
madge is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 0.0.0 - 4.0.1.
0.0.0 - 4.0.1
Low

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
rc
Version ^1.2.8
—
—
ora
Version ^5.4.1
—
—
chalk
Version ^4.1.2
—
—
debug
Version ^4.3.4
—
—
walkdir
Version ^0.4.1
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
14 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform