utility library for parsing asn1 files for use with browserify-sign.
67%
Total Score
75
50
89
50
50
No build attestation or trusted-publisher provenance is present, leaving the origin of the published artifact less independently verifiable.
Five runtime dependencies are a moderate dependency surface for this small utility, creating some transitive maintenance exposure without evidence of an excessive profile.
The package has prepack and prepublish lifecycle scripts, adding build-time behavior that dependents should account for, although these are not inherently unsafe.
The repository recorded zero commits and zero active maintainers over the past three months, a meaningful sign of currently paused maintenance despite the recent release.
No build tools or security scanning tools were detected, reducing automated maintenance and security assurance for the project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pbkdf2 Version ^3.1.5 | — | — |
asn1.js Version ^4.10.1 | — | — |
safe-buffer Version ^5.2.1 | — | — |
browserify-aes Version ^1.2.0 | — | — |
evp_bytestokey Version ^1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.