Spec-compliant shim for Symbol.prototype.description proposal.
78%
Total Score
75
100
100
67
50
No build attestation or trusted-publisher identity is present. This weakens publication transparency, but it is not by itself evidence that the release is unsafe.
The package uses prepack and prepublish lifecycle scripts, which add build-time execution during publication. This is a modest supply-chain hygiene concern, not evidence that installation executes a script.
There were no commits or active maintainers in the last 3 months. That is a maintenance caution, though the recent release and January 2026 push partly compensate for the short observation window.
All 5 workflows were analyzed without audit findings or untrusted checkouts, and pull_request_target is used without a detected sink. However, all 5 action references are unpinned, leaving a reproducibility and action-substitution gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gopd Version ^1.2.0 | — | — |
call-bind Version ^1.0.8 | — | — |
es-errors Version ^1.3.0 | — | — |
has-symbols Version ^1.1.0 | — | — |
es-object-atoms Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.