elegant & feature rich browser / node HTTP with a fluent API
78%
Total Score
healthy
Healthy, with strong project backing and a current release despite no recorded commits in the last three months.
The release has no attestation or trusted-publisher provenance, leaving the build and publication chain less independently verifiable. This is a transparency limitation, not a health verdict by itself.
A prepare script runs during installation or package preparation, adding some install-time complexity. No provided signal shows that it performs unsafe behavior, so the concern is limited.
No commits or active maintainers were recorded in the last three months, which is a maintenance warning. However, the repository was pushed on the assessment date and the release includes version-specific fixes, partly offsetting the concern.
The repository uses established build tooling and multiple packaging systems, but no security scanning tools were detected. The missing scanning is a modest hygiene gap.
The package ships no type declarations. That reduces TypeScript ergonomics for consumers, although it is a consumer-compatibility gap rather than evidence of abandonment.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-16129 superagent is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 3.7.0. | 0.0.0 - 3.7.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
qs Version ^6.14.1 | — | — |
mime Version 2.6.0 | — | — |
debug Version ^4.3.7 | — | — |
methods Version ^1.1.2 | — | — |
cookiejar Version ^2.1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.