Dynamic ES module loader
62%
Total Score
75
100
90
67
50
No build attestation or trusted-publisher provenance is present. This limits publication transparency, although the package has a clear repository and a simple dependency profile.
The package has 236 releases over roughly 12 years, but its latest registry release was over two years ago and there were no releases in the last 12 months. That substantially raises maintenance and abandonment concerns.
The repository recorded zero commits and zero active maintainers in the last three months. Although the repository is not archived and was pushed more recently, the lack of recent commit activity weakens evidence of ongoing maintenance.
The repository has no published security policy. This is a transparency and vulnerability-reporting gap, though it is less significant than the release and commit-activity concerns.
Both workflows were analyzed completely with no reported findings or untrusted checkout or script-injection sinks. However, all 7 action references are unpinned, which weakens build reproducibility and supply-chain hygiene; the pull_request_target trigger is not dangerous without a corresponding sink.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.