richer JavaScript errors
64%
Total Score
75
100
83
88
50
No build attestation or trusted-publisher provenance is present, leaving publication origin less transparent. This is a supply-chain hygiene gap, though not a health verdict by itself.
The package has 23 releases over more than 14 years, but no releases in the last 12 months and its latest release was nearly 5 years ago. This indicates materially slowed maintenance despite its long history.
The repository recorded zero commits and zero active maintainers in the last 3 months. This supports the release-history concern and indicates little current maintenance activity.
The repository uses Make but reports no security-scanning tools. The build setup is present, while the missing scanning coverage is a modest transparency and hygiene gap.
No repository security policy is present, leaving vulnerability reporting expectations unclear. The gap matters for maintenance transparency but is not severe for this small, mature library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
extsprintf Version ^1.2.0 | — | — |
assert-plus Version ^1.0.0 | — | — |
core-util-is Version 1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.