the bare-bones internationalization library used by yargs
78%
Total Score
88
100
83
80
A prepare install-time script adds some build-time supply-chain exposure, although the package has zero runtime dependencies and the repository shows standard build tooling.
The package has 22 releases since 2015, but the registry shows no release in about 5 years, which raises a currency concern despite recent repository activity.
All 6 recent commits came from one contributor, creating a real continuity risk, though the repository is owned by an organization that can provide some handoff capacity.
The project uses TypeScript, npm scripts, and Babel for builds, but no security scanning tools were detected, leaving a modest assurance gap.
Neither workflow declares top-level token permissions, so the repository has weaker explicit least-privilege controls even though no workflow requests top-level write access.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-7774 y18n is vulnerable to Improper Input Validation in versions 0.0.0 - 3.2.2, 4.0.0 - 4.0.0 and 5.0.0 - 5.0.5. | 0.0.0 - 3.2.24.0.0 - 4.0.05.0.0 - 5.0.5 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.