Missing ECMAScript module utils for Node.js
78%
Total Score
67
100
95
67
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful sign of slowed development despite a recent push and current release.
There are active issues and pull requests, including eight new pull requests in the last month, although none were merged in that period; this is a modest maintenance caution rather than abandonment evidence.
The project uses TypeScript and a build tool, but no security scanning tools were detected; this is a limited security-process gap rather than a direct dependency risk.
No repository security policy was found, reducing transparency about vulnerability reporting and response practices.
All workflows were analyzed with no high- or medium-severity findings and no dangerous triggers or sinks. Three of six action references are unpinned and both workflows install packages outside a lockfile, creating low-severity reproducibility and supply-chain hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ufo Version ^1.6.3 | — | — |
acorn Version ^8.16.0 | — | — |
pathe Version ^2.0.3 | — | — |
pkg-types Version ^1.3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.