JavaScript parser, mangler/compressor and beautifier toolkit for ES6+
84%
Total Score
75
94
88
The package uses a prepare install-time lifecycle script. This is not inherently unsafe, but it increases installation complexity compared with a package having no lifecycle scripts.
One contributor made 100% of the 26 recent commits. The organization-owned repository provides some handoff capacity, but the observed maintenance activity is still highly concentrated.
There were 26 commits in the last 3 months, showing ongoing development. However, all were made by one active maintainer, which limits resilience.
The repository uses build tooling, but no security-scanning tools were detected. This is a transparency and assurance gap, though it is partly offset by the repository's other maintenance evidence.
| Title | Versions | Severity |
|---|---|---|
CVE-2022-25858 terser is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 4.8.1 and 5.0.0 - 5.14.2. | 0.0.0 - 4.8.15.0.0 - 5.14.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
acorn Version ^8.15.0 | — | — |
commander Version ^2.20.0 | — | — |
source-map-support Version ~0.5.20 | — | — |
@jridgewell/source-map Version ^0.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.