← Rankings

node-ipc

npm · Rank #210 of 217

64 / 100 D
STALE — No release in 678 days. Stale packages accumulate unpatched vulnerabilities.
1
npm publisher
Single point of failure
849K
downloads/week
Blast radius if compromised
12.3y
package age
Established package
678 days ago
last release
Possibly unmaintained
35
GitHub contributors
Many contributors, single publisher
Provenance Not enabled
Staged Publishing Not enabled
⚠️ Dormant Access 1 inactive publisher with npm access

Risk analysis

node-ipc has not published a release in over 12 months. Stale packages accumulate vulnerabilities and may indicate abandonment.

What the score measures

  • Publisher depth — How many people can push to npm? Single-publisher packages are the #1 structural risk.
  • Longevity — Older packages have track records. New packages with high adoption are higher risk.
  • Release consistency — Regular releases signal active oversight. Long gaps mean unpatched vulnerabilities.
  • Download trend — Growing packages attract more scrutiny (and more attacks).
  • OpenSSF Scorecard — Process security: branch protection, code review, CI/CD safety.
  • Build provenance — Published versions linked to specific CI runs via SLSA attestation.
  • Staged publishing — Human approval gate between npm publish and going live.

node-ipc is one package. Score them all.

You came looking for node-ipc. Your node_modules has hundreds more. Run one command to score every dependency you ship:

npx proof-of-commitment

Auto-detects your lockfile. Scores every dependency. Zero install.

Share this score

Add the badge to your README

Commit trust score for node-ipc
![Commit Trust](https://getcommit.dev/badge/npm/node-ipc)