Create graphs from module dependencies.
62%
Total Score
50
88
50
The package has 77 releases since May 2012, but none in the last 12 months and the latest release was in August 2024. Its long history helps, but the recent release gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful sign of currently limited development activity, despite the repository being recently pushed according to its archive-status signal.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is less significant than the maintenance signals and does not by itself make the release unfit.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but both action references are unpinned and it installs a package outside a lockfile. The low-severity high-confidence finding is a build-hygiene caution, not a severe risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-23352 madge is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 0.0.0 - 4.0.1. | 0.0.0 - 4.0.1 | Low |
| Dependency | Last Release | Score |
|---|---|---|
rc Version ^1.2.8 | — | — |
ora Version ^5.4.1 | — | — |
chalk Version ^4.1.2 | — | — |
debug Version ^4.3.4 | — | — |
walkdir Version ^0.4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.