Node.JS path module
45%
Total Score
33
50
78
88
50
The latest registry release was about 11 years ago, with no releases in the past 12 months. This is strong evidence of abandonment despite the package's long history.
The repository recorded no commits and no active maintainers in the past 3 months. Combined with the old registry release, this materially increases abandonment risk.
No build attestation or trusted-publisher provenance is present. This leaves publication origin less transparent, although it is not evidence that the release is unsafe.
The package declares two runtime dependencies, util and process, for a small compatibility module. This adds dependency surface to an otherwise minimal artifact.
The repository is owned by an individual user rather than an organization. That does not make the package unhealthy, but it provides no organizational backing to compensate for the thin recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
util Version ^0.10.3 | — | — |
process Version ^0.11.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.