Package Health

source-map-js

Generates and consumes source maps

Latest 1.2.2NPMNPM

68%

Total Score

caution

Usable with caveats: no commits in three months and a single registry maintainer limit maintenance depth.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher identity was detected, so the release has limited verifiable publication provenance.

Maintainerscaution

Only one registry account has publish access, creating limited publishing redundancy; the linked repository is user-owned, so no organizational backing compensates for that concentration.

Release historycaution

The package has existed since 2021 and released version 1.2.2 recently, but only one release appeared in the last 12 months, indicating a modest maintenance cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months, a meaningful sign of thin recent development activity despite the recent release.

Repo toolingcaution

The project uses webpack and npm scripts, but no security-scanning tooling was detected, leaving a modest repository hygiene gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-93749
source-map-js is vulnerable to Improper Validation of Specified Quantity in Input in versions 1.0.0 - 1.2.2.
1.0.0 - 1.2.2
High

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 days ago
Created
5 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform