Open stuff like URLs, files, executables. Cross-platform.
88%
Total Score
75
100
95
90
50
No build attestation or trusted-publisher provenance is present, which weakens publication transparency, but the package has a long release history and an active matching repository.
The repository is owned by an individual rather than an organization, so the one-person publishing and concentrated contribution pattern represents a real continuity limitation.
Two contributors were active, but the primary contributor made 7 of 8 recent commits, leaving maintenance substantially concentrated and creating a moderate continuity risk.
The repository reports no build tools or security-scanning tools. This is a transparency and assurance gap, although the small package and active maintenance partly limit its significance.
The only workflow does not declare top-level token permissions, so its effective permissions are less explicit than preferred even though no write permissions were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
is-in-ssh Version ^1.0.0 | — | — |
wsl-utils Version ^1.0.0 | — | — |
default-browser Version ^5.5.1 | — | — |
define-lazy-prop Version ^3.0.0 | — | — |
powershell-utils Version ^0.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.