Healthy and suitable to use. It has frequent releases, recent repository activity, tested and documented source, type declarations, and npm provenance; the main caveats are the missing package README, no security policy, and a repository name that does not explicitly identify this package.
88%
Total Score
100
100
90
88
100
The artifact lacks a README, but the repository has tests and a changelog, uses GitHub Releases, and provides release notes for this exact version. The missing artifact README is a minor consumer-documentation gap rather than an abandonment signal.
The repository name does not match slate-dom and its README does not mention the package, so the package-to-repository association is less transparent. This can be ordinary for a monorepo, but the missing explicit mention warrants caution.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap, not evidence that the package is unsafe.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10769 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. slate-dom is vulnerable to Prototype Pollution in versions 0.111.0 - 0.124.0. | 0.111.0 - 0.124.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
direction Version ^1.0.4 | — | — |
is-hotkey Version ^0.2.0 | — | — |
tiny-invariant Version 1.3.1 | — | — |
is-plain-object Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.