Store information about any JS value in a side channel. Uses WeakMap if available.
79%
Total Score
50
50
100
75
50
No build attestation, trusted publisher, or staged publishing is recorded. This limits publication transparency, but it is a provenance gap rather than evidence that the package is unhealthy.
Five runtime dependencies, including alternative side-channel implementations, create some transitive maintenance exposure for a small utility package. The profile is not excessive enough to indicate a serious health problem.
The package has prepack and prepublish scripts. These are build-time publication hooks rather than install-time execution, so they add limited review surface but are not a major adoption concern.
The repository is owned by an individual rather than an organization, so the single registry maintainer does not benefit from visible organizational backing. Other repository evidence shows the project is nevertheless directly maintained by that owner.
There were no commits and no active maintainers in the last three months. The recent release and push partly compensate, but the lack of recent development activity is a maintenance caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
es-errors Version ^1.3.0 | — | — |
object-inspect Version ^1.13.4 | — | — |
side-channel-map Version ^1.0.1 | — | — |
side-channel-list Version ^1.0.1 | — | — |
side-channel-weakmap Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.