Synchronous version of the Fetch API
78%
Total Score
60
100
89
80
50
No build attestation or trusted-publisher provenance is present, limiting publication transparency, but this is a transparency gap rather than evidence of abandonment.
Only one registry account has publish access, creating a continuity concern, though repository activity shows that this maintainer is currently active.
The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the narrow maintainer base.
All 2 recent commits came from one contributor, so the project has a low bus factor and could become difficult to maintain if that contributor stops.
There were 2 commits in the last 3 months, showing recent maintenance, though the activity is light and concentrated in one active maintainer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
node-fetch Version ^3.3.2 | — | — |
timeout-signal Version ^2.0.0 | — | — |
whatwg-mimetype Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.