path-equal 1.2.8 appears safe to depend on from a supply-chain health perspective. It is a mature package released since 2018, has three releases in the last 12 months, is not deprecated, uses a stable major version, and has current repository activity with 26 commits and 19 merged pull requests in the last month. The package has an MIT license, type declarations, no runtime dependencies, npm provenance, matching repository documentation, repository tests and changelog coverage, security scanning, and a security policy. The main concerns are a small two-contributor recent maintainer base, low repository popularity, and workflows lacking top-level token permission declarations, but these are moderated by organization backing, a second active contributor, job-level permissions in two workflows, and the absence of detected dangerous workflow patterns.
88%
Total Score
100
100
95
90
100
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.