A practical functional library for JavaScript programmers.
73%
Total Score
83
100
89
75
The package uses a prepare script, which can run during installation or publishing and deserves review. No provided signal shows that it performs unsafe behavior, so this is only a mild supply-chain consideration.
The repository recorded zero commits and zero active maintainers over the last three months. Although pull requests were merged and the repository was recently pushed, the lack of recent commit activity is a meaningful maintenance warning.
The repository uses established build tools, but no security scanning tools were detected. Build automation is present; the missing scanning is a modest transparency and hygiene gap.
No type declarations are included, which adds integration work for TypeScript consumers. This is a consumer-ergonomics gap rather than evidence of weak maintenance.
Both workflows were analyzed with no audit findings, no untrusted checkouts, and no script injection; one workflow scopes permissions at job level. However, all four analyzed action references are unpinned, leaving avoidable reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.