Spec-compliant polyfill for String.prototype.matchAll
82%
Total Score
90
50
100
83
50
No build attestation is present, so consumers cannot independently verify this release's build origin. Staged publishing and a named approver provide some process control but do not provide verifiable provenance.
Thirteen runtime dependencies create a meaningful dependency surface for a small shim, increasing maintenance and transitive-risk exposure even though the package has a long release history.
All 14 recent commits came from one contributor, creating a real continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off.
All six workflows were analyzed with no reported audit findings, five workflows use read-only permissions, and the pull_request_target workflows have no untrusted checkouts or script-injection sinks. However, all six action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gopd Version ^1.2.0 | — | — |
call-bind Version ^1.0.9 | — | — |
es-errors Version ^1.3.0 | — | — |
call-bound Version ^1.0.4 | — | — |
es-abstract Version ^1.24.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.