The smallest and fastest pixel-level image comparison library.
82%
Total Score
healthy
Active, well-documented package with strong organization backing but concentrated recent maintenance and unpinned workflow actions.
One contributor made 100% of the four commits in the last three months, leaving recent maintenance dependent on a single person despite organization ownership.
Four commits were made in the last three months, so activity has not stopped, although all were made by one active maintainer.
The project uses TypeScript build tooling, but no security scanning tools were detected; this is a modest transparency gap rather than a severe dependency-health concern.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pngjs Version ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.