nlcst utility to transform a tree to a string
68%
Total Score
83
100
90
80
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less transparent, though this is not by itself evidence that the package is unsafe.
One of two workflows uses pull_request_target, which can require elevated trust handling and increases workflow-maintenance risk even though no untrusted checkout or script injection was detected.
The package has a long history with 21 releases, but its latest release was about three years ago and there were no releases in the last 12 months, lowering confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, reinforcing the concern that maintenance has slowed or stopped.
The repository uses TypeScript and npm build tooling, but no security-scanning tools were detected, leaving a modest security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@types/nlcst Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.