Scanning package - this fetches live data from the registry and GitHub, so it can take a few seconds…
Scanning package - this fetches live data from the registry and GitHub, so it can take a few seconds…
risk score 0/100 - 0 from supply-chain heuristics · 0 from known vulnerabilities
Supply-chain / malicious-intent signals - typosquatting, maintainer takeovers, install scripts, and similar.
Published CVE/GHSA advisories for this exact version, via OSV.dev - independent of the findings above. A package can have no supply-chain findings and still carry a known vulnerability.
Recursively checks this package's dependencies (and their dependencies) for known issues - e.g. "this package is fine, but depends on X which has a CVE."