Update notifications for your CLI app
65%
Total Score
50
50
81
83
50
No build attestation or trusted-publisher provenance is present, limiting publication transparency. This is a supply-chain hygiene gap rather than evidence that the release is unsafe.
Ten runtime dependencies add meaningful transitive maintenance surface for a small utility, though the profile is not extreme enough to indicate a severe concern on its own.
The repository is owned by an individual rather than an organization, so there is no shown organizational backing to compensate for the concentrated recent contribution pattern.
The package has 53 releases over nearly 14 years, but no registry release in the last 12 months and its latest release was in September 2024, which weakens confidence in ongoing maintenance.
All recent repository activity comes from one contributor, creating a concentrated maintenance dependency; the individually owned project provides no organizational handoff evidence to offset it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pupa Version ^3.1.0 | — | — |
boxen Version ^8.0.1 | — | — |
chalk Version ^5.3.0 | — | — |
is-npm Version ^6.0.0 | — | — |
semver Version ^7.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.