Fake XHR and server
68%
Total Score
63
100
100
63
50
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful maintenance concern despite the recent registry release and recent push timestamp.
No build attestation or trusted-publisher provenance is available, leaving publication origin less independently verifiable, though this is a transparency gap rather than evidence of compromise.
A prepare script runs during installation or packaging, which adds some supply-chain execution surface, but this signal alone does not show harmful behavior or an excessive lifecycle setup.
Three pull requests were opened in the last month, but none were merged and no issues were closed, suggesting activity without demonstrated throughput.
No security policy is present, reducing transparency for vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
just-extend Version ^6.2.0 | — | — |
path-to-regexp Version ^8.3.0 | — | — |
@sinonjs/commons Version ^3.0.1 | — | — |
@sinonjs/fake-timers Version ^15.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.