Dynamic require
Supply chain riskDynamic require can indicate the package is performing dangerous or unsafe dynamic code execution.
No contributors or author data
MaintenancePackage does not specify a list of contributors or an author in package.json.
Empty package
Supply chain riskPackage does not contain any code. It may be removed, is name squatting, or the result of a faulty package publish.
No README
QualityPackage does not have a README. This may indicate a failed publish or a low quality package.
No repository
Supply chain riskPackage does not have a linked source code repository. Without this field, a package will have no reference to the location of the source code use to generate the package.
No tests
QualityPackage does not have any tests. This is a strong signal of a poorly maintained or low quality package.
17466
4048.69%5
400%97
Infinity%2
-33.33%1
-50%43
Infinity%0
-100%5
Infinity%3
Infinity%2
100%