Patch console methods to intercept output
62%
Total Score
50
100
89
63
50
No build attestation or trusted-publisher provenance is present, reducing release transparency, but this is a moderate gap rather than evidence that the artifact is unsafe.
A prepare script runs during installation, adding build-time behavior that should be understood by consumers, though this signal alone is not a severe dependency risk.
Only one registry account has publish access, leaving little publishing redundancy, although the linked repository is also owned by that individual.
The package has only two releases and none in the last 12 months; its latest release was published in February 2022, indicating a long inactive period for a maintained dependency.
There were no commits and no active maintainers in the measured three-month period, reinforcing the evidence that maintenance has stopped or substantially slowed.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.