One promise for multiple requests in flight to avoid async duplication
55%
Total Score
50
79
83
The package includes a consumer-facing README, while the missing tests are explicitly acknowledged and are normal to omit from a published artifact. The repository also has no tests, which weakens maintenance confidence for future changes.
The package has had only two releases, with the latest published in February 2017 and none in nearly nine years. This may reflect a stable tiny utility, but it substantially limits evidence of ongoing maintenance.
There were no commits and no active maintainers in the last three months. For a package unchanged since 2017 this may be intentional, but it leaves little evidence of current maintenance capacity.
The repository reports no build tools and no security scanning tools. That is less concerning for a four-file JavaScript utility, but it still reduces transparency around verification and security practices.
No security policy is present. This is a hygiene and support gap rather than a severe risk for this small package, but it provides no documented process for handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.