| 01 |
Package exists |
safe |
Package 'semver' (version '7.3.5') exists in the npm registry. |
| 02 |
Known vulnerability |
caution |
[email protected] is affected by a known vulnerability (GHSA-c2qf-rxjj-qqgw): semver vulnerable to Regular Expression Denial of Service |
| 03 |
No install scripts |
safe |
Package 'semver' declares no preinstall/install/postinstall scripts. |
| 04 |
Typosquat recognized package |
safe |
'semver' is itself a popular npm package (>= 100000 weekly downloads), not a typosquat. |
| 05 |
No combosquat match |
safe |
Name 'semver' is not a popular package name with a generic affix attached. |
| 06 |
Scope not evaluated |
safe |
Scope confusion was not evaluated for 'semver': it has no separator to split into a scope and a package name. Absence of a finding here is not evidence the name is unlike a scoped package's. |
| 07 |
Source repository present |
safe |
'semver' declares a source repository (git+https://github.com/npm/node-semver.git). The declaration is unverified: pkgproof does not confirm the repository exists or that it publishes this package. |
| 08 |
Reputation |
safe |
'semver': first published 5662 days ago, 832321560 weekly downloads, 119 releases, the most recent 55 days ago. |