sindresorhus/is-plain-obj
56/100
// this URL always shows the latest public scan for this repo. permanent permalink to this specific scan: www.codeclanker.com/scan/id/7dLh8apU
// 4 public scans exist for this repo — view full history
// 4 public scans exist for this repo — view full history
Security
Secrets, committed configuration and the tooling the repository uses to police itself.
medium
No lockfile committed
Dependency versions are declared as ranges, so two installs can resolve to different code and transitive dependencies could not be checked at all. Commit the lockfile your package manager produces.
medium
No start command is declared anywhere
The repository has a server entrypoint but no start script, Procfile, Docker CMD or platform config saying how to run it. Buildpacks guess, and guess differently from each other, so the first deploy either starts the wrong process or none at all.
index.js
What was scanned
- every file scanned for secrets — 14 in total, none skipped
- 3 dependencies from manifests only — no lockfile, transitive deps unchecked
- deploy checks read 4 shipping file(s), 0 bind site(s) and 0 environment variable(s)
- code quality parsed 4 source file(s), 125 lines, ESLint over 4
- the AI scored from manifests and the file tree; it did not read source itself
Security tooling detected in the repository: security policy