A comprehensive library for mime-type mapping
74%
Total Score
50
100
90
80
The repository is owned by an individual account rather than an organization, so the single registry maintainer is consistent with a small project but indicates limited visible institutional backing.
The package has existed for about 15 years with 58 releases, but it has had no registry release in the last 12 months despite version 4.1.0 being published in September 2025; this lowers confidence in current release cadence.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful sign of currently slow maintenance. The recent push and published 4.1.0 release provide some compensating evidence but do not remove the cadence concern.
The project uses TypeScript and npm build tooling, showing a reproducible build structure, but it has no detected security-scanning tool.
No security policy was found in the repository, leaving vulnerability-reporting expectations less transparent.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-16138 mime is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 1.4.1 and 2.0.0 - 2.0.3. | 0.0.0 - 1.4.12.0.0 - 2.0.3 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.