small xhr abstraction
62%
Total Score
50
89
83
50
No build attestation or trusted-publisher provenance is present, so consumers have limited evidence connecting the published artifact to its source build. This is a transparency weakness, not proof of unsafe behavior.
The package has 60 releases over more than 14 years, but no registry release in the past year and its latest release is nearly six years old. This materially raises staleness risk despite the long historical release record.
There were no commits and no active maintainers in the measured three-month window. The repository's May 2025 push shows it is not abandoned outright, but recent development activity is currently limited.
There were no new or closed issues or pull requests in the past month, with 10 open issues and 3 open pull requests. This suggests limited current project responsiveness.
The repository uses a build tool, but no security-scanning tools were detected. For a small package this is a modest hygiene gap rather than a severe maintenance risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
xtend Version ^4.0.0 | — | — |
global Version ~4.4.0 | — | — |
is-function Version ^1.0.1 | — | — |
parse-headers Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.