parse SPDX license expressions
72%
Total Score
67
100
93
67
All recent commits came from one contributor, creating a narrow current maintenance base; organization backing partly offsets the handoff risk.
Two commits in the last three months show some continuing activity, though the volume is modest for an established project.
The repository has no security policy, leaving vulnerability-reporting expectations unclear, although this is a transparency gap rather than evidence of unsafe code.
No type declarations are included, which is a real integration gap for TypeScript consumers of this JavaScript library.
The sole workflow was fully analyzed with no injection or high-confidence audit findings, but both referenced actions are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spdx-exceptions Version ^2.1.0 | — | — |
spdx-license-ids Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.