A minimal DOM implementation
68%
Total Score
50
100
89
83
50
The release has no build attestation, trusted publisher, or staged-publishing evidence, so registry artifacts cannot be independently tied to a recorded build. The matching source tree and recent release provide some compensating transparency.
The repository recorded 0 commits and 0 active maintainers in the last three months, which weakens evidence of ongoing maintenance. The release was still published recently, so this is a caution rather than an abandonment verdict.
There were 0 new or closed issues and 0 merged pull requests in the last month, with 10 open issues and 3 open pull requests. This indicates limited recent project activity, although open work remains visible.
The repository reports no build tools and no security scanning tools. For this small JavaScript package, that is a transparency and hygiene gap, but it does not by itself indicate that the package is unfit.
No security policy was found in the linked repository, leaving vulnerability-reporting expectations undocumented. This is a maintenance and transparency gap, not evidence of malicious behavior.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-57352 min-document is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 2.19.0. | 0.0.0 - 2.19.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
dom-walk Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.