Resolve the path of a module like `require.resolve()` but from the current working directory
68%
Total Score
67
100
89
83
The linked repository is owned by an individual rather than an organization, so there is no organizational backing signal to offset the thin maintenance evidence.
The package is mature but has only three releases, with no releases in the last 12 months and the latest release dating to April 2019; this indicates a long period without published maintenance.
There were no commits and no active maintainers in the measured three-month period, consistent with an inactive project and increasing abandonment risk.
No build tools or security-scanning tools were detected. For this small package that is a hygiene limitation rather than a severe risk, but it reduces evidence of modern project controls.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or audit failures. Both action references are unpinned, which weakens build reproducibility but is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
resolve-from Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.