SockJS-client is a browser JavaScript library that provides a WebSocket-like object.
62%
Total Score
83
100
90
83
50
No build attestation or trusted-publisher provenance is present, leaving publication origin less independently verifiable. This is a transparency and supply-chain hygiene gap, not evidence that the release is unsafe.
The package has 32 releases over nearly 14 years, but no release in the last 12 months and the latest release was in May 2022. This materially raises freshness and abandonment concerns for a dependency.
There were zero commits and zero active maintainers in the last three months, indicating little recent development activity. The recent repository push and organization backing partly compensate, but do not restore a normal release cadence.
The repository uses build tooling including Gulp, esbuild, and npm scripts, but no security scanning tools were detected. The build setup supports maintainability while the missing scanning is a modest hygiene gap.
Both workflows were fully analyzed with no audit findings, no dangerous triggers, and no broad write permissions. However, all three action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^3.2.7 | — | — |
inherits Version ^2.0.4 | — | — |
url-parse Version ^1.5.10 | — | — |
eventsource Version ^2.0.2 | — | — |
faye-websocket Version ^0.11.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.