sindresorhus/is-plain-obj
— /100
// permalink — this URL always shows scan
// a newer public scan exists: www.codeclanker.com/scan/sindresorhus/is-plain-obj
Oxcnx5ls from 2026-08-27, even if a newer public scan exists for this repo.// a newer public scan exists: www.codeclanker.com/scan/sindresorhus/is-plain-obj
Security
Secrets, committed configuration and the tooling the repository uses to police itself.
medium
No lockfile committed
Dependency versions are declared as ranges, so two installs can resolve to different code and transitive dependencies could not be checked at all. Commit the lockfile your package manager produces.
What was scanned
- every file scanned for secrets — 15 in total, none skipped
- 3 dependencies from manifests only — no lockfile, transitive deps unchecked
- the AI scored from manifests and the file tree; it did not read source itself
Security tooling detected in the repository: security policy