@cyberhub/trust-pnpm-semver.peer-range
v1.0.0
Published
Security Trust Report for @pnpm/semver.peer-range — 67/100 (B, standard). Maintainer risk and vulnerability analysis from 8 security databases.
Maintainers
Readme
Security Trust Report: @pnpm/semver.peer-range
Score: 67/100 | Grade: B | Tier: STANDARD
This package has notable risk factors. Review flags below.
Score Breakdown
| Category | Score | |----------|-------| | Maintainer Trust | 68/100 | | Package Health | 94/100 | | Supply Chain | 56/100 | | Community | 40/100 |
Vulnerabilities
No known vulnerabilities.
Flags
- HIGH: Depends on historically compromised package: semver
- HIGH: 1 direct dependencies have known security issues
- HIGH: Depends on "semver" which has ReDoS CVE-2022-25883
- MEDIUM: Maintainer has only published 1 version(s)
- MEDIUM: Package dormant — last published 422 days ago
- MEDIUM: No GitHub repo found — community signals unavailable
- INFO: Published with 2FA enabled (signed)
- INFO: Package has provenance signatures
- INFO: No known vulnerabilities across 8 security databases
Maintainers
- pnpmuser (2FA)
- zkochan (2FA)
