sindresorhus/is-plain-obj

57/100
// permanent record of scan from 2026-08-27 · classified as library · stack: JavaScript · Node.js >=18 · ESM · ava · tsd · xo
// permalink — this URL always shows scan EfZGyhkO from 2026-08-27, even if a newer public scan exists for this repo.
// a newer public scan exists: www.codeclanker.com/scan/sindresorhus/is-plain-obj

Security

Secrets, committed configuration and the tooling the repository uses to police itself.

medium

No lockfile committed

Dependency versions are declared as ranges, so two installs can resolve to different code and transitive dependencies could not be checked at all. Commit the lockfile your package manager produces.

What was scanned

Security tooling detected in the repository: security policy

Scan your own repo

Free 60-second scan. No signup.

Run a free scan →