Variant of merge that's useful for webpack configuration
68%
Total Score
63
100
89
75
50
No build attestation or trusted-publisher identity is available, leaving release provenance less transparent even though this is not itself evidence of an unhealthy project.
A prepare script runs during package lifecycle, which adds some install-time behavior, but this signal alone does not show that the behavior is unsafe or unusually complex.
The registry reports zero publishing-access accounts, which limits transparency about who can publish releases. This is partly offset by the linked repository being owned by an organization, so it is a minor concern rather than evidence of abandonment.
The package has 91 releases over more than 11 years, but its latest release was over two years ago and it had no releases in the last 12 months, indicating slowed maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has gone quiet. The long release history and existing project structure provide some maturity compensation but do not remove the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
flat Version ^5.0.2 | — | — |
wildcard Version ^2.0.1 | — | — |
clone-deep Version ^4.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.