sql named placeholders to unnamed compiler
78%
Total Score
75
100
94
83
100
There were no commits from active maintainers in the last three months, which indicates limited recent development activity. Recent release and pull-request signals partly offset this, so the concern is moderate rather than severe.
No type declarations are published, which makes integration less convenient for TypeScript consumers. The package is a small JavaScript query utility, so this is a minor ergonomics gap rather than a maintenance risk.
All four workflows were analyzed with no audit findings, and no untrusted checkout or script-injection paths were detected. However, all 11 analyzed action references are unpinned and one workflow has top-level write permissions, creating a workflow hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lru.min Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.