A Vite plugin to polyfill Node's Core Modules for browser environments.
63%
Total Score
50
100
94
88
50
No build attestation or trusted-publisher identity is present, so consumers cannot verify provenance from the supplied registry metadata. This reduces publication transparency but is not independently disqualifying.
Only one registry account has publishing access, creating a thin publishing base. The package's long release history partly compensates, but it does not remove single-person continuity risk.
The repository is owned by an individual account rather than an organization, so there is no demonstrated organizational continuity beyond the observed release history.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance slowdown despite the recent release history.
There were no new or closed issues or pull requests in the last month, while 41 issues and 6 pull requests remain open. Combined with zero recent commits, this suggests unattended project work.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
node-stdlib-browser Version ^1.3.1 | — | — |
@rollup/plugin-inject Version ^5.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.