@web3api/tracing-js
MITLicense declared in the package manifest.Web3API Core Tracing
63
Security score
0 known advisories in v0.0.1-prealpha.85
OpenSSF Scorecard 1.1/10
Weekly downloads
Downloads across all versions in the last 7 days, from the official npm downloads API (api.npmjs.org).—
Unpacked size
Size of v0.0.1-prealpha.85 on disk after npm install extracts the tarball, as reported by the npm registry.16.4 kB
Dependencies
Direct runtime dependencies declared by v0.0.1-prealpha.85. Transitive dependencies are not counted here — use the lockfile audit for the full tree.11
Last publish
When v0.0.1-prealpha.85 was published to the registry. Long gaps can indicate an unmaintained package.4 years ago
Security advisories
Vulnerabilities affecting v0.0.1-prealpha.85 specifically, from OSV.dev — the open database aggregating the GitHub Advisory Database (GHSA) and CVEs. Links open the full advisory.No known vulnerabilities affect v0.0.1-prealpha.85.
OpenSSF ScorecardJul 20, 2026
OpenSSF Scorecard is an automated audit of the source repository's security practices, run by the Open Source Security Foundation. Each check scores 0-10; hover a check for what it means. Data via deps.dev.- MaintainedThe project shows recent activity: commits or issue triage within the last 90 days.Result: 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 00
- Code-ReviewChanges are reviewed by another maintainer before landing on the main branch.Result: Found 5/16 approved changesets -- score normalized to 33
- CII-Best-PracticesThe project holds an OpenSSF Best Practices badge, a self-certification of security practices.Result: no effort to earn an OpenSSF best practices badge detected0
- Dangerous-WorkflowGitHub Actions workflows avoid dangerous patterns such as untrusted code checkout or script injection.Result: dangerous workflow patterns detected0
- Token-PermissionsCI workflow tokens follow least privilege — read-only unless a job needs more.Result: detected GitHub workflow tokens with excessive permissions0
- Binary-ArtifactsNo compiled binaries are committed to the repository — binaries can't be reviewed and may hide malicious code.Result: binaries present in source code0
- Security-PolicyA SECURITY.md explains how to report vulnerabilities privately.Result: security policy file not detected0
- LicenseThe project publishes a license file.Result: license file detected10
- FuzzingThe project is fuzz-tested (e.g. OSS-Fuzz), which finds crashes and memory bugs automatically.Result: project is not fuzzed0
- Signed-ReleasesRelease artifacts are cryptographically signed so consumers can verify their origin.Result: Project has not signed or included provenance with any releases.0
- SASTStatic analysis (e.g. CodeQL) runs on pull requests to catch bugs before merge.Result: SAST tool detected but not run on all commits7
- Pinned-DependenciesBuild dependencies are pinned to exact versions or hashes, preventing silent supply-chain swaps.Result: dependency not pinned by hash detected -- score normalized to 00