Better localStorage
65%
Total Score
50
100
89
88
50
No build attestation or trusted-publisher provenance is present, so consumers have limited evidence connecting the published artifact to its build process.
Only one account has registry publish access. That is not proof of abandonment, but it leaves a thin visible publishing base when recent release activity is also absent.
The repository is owned by an individual rather than an organization, so the one-account maintainer base provides limited visible project backing.
The package has a long history with 46 releases, but it has had no release in the past 12 months; the latest release was in December 2024, indicating slower maintenance.
The repository recorded zero commits and zero active maintainers over the past three months, a concrete sign of slowed development and increased abandonment risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-57556 store2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.14.4. | 0.0.0 - 2.14.4 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.