90OUT OF 100
TrustedHigh trustStatic read

npm/left-pad

Scored 90/100 (Trusted). No code signals were flagged on the static read. The package left-pad is a foundational, long-standing utility with no malicious behavior observed in our static read. The code is simple, transparent, and consistent with its declared intent. Full runtime behavior was not executed in a sandbox on this pass.

Repository size
0 KB
Packages
0
Stars
—
Created
2014-03-14
Reputation signals
npm avatar
left-pad
npm · published by @stevemao
Publisher@stevemao
Maintainers (2)stevemao, westlac
First published12 yr 6 mo ago
Weekly downloads3.2M
Versions published15
LicenseWTFPL
Code & behavior signals
No risky items found

No signatures, install hooks, obfuscation, or embedded secrets were found in the code.

Per-package scoring
Final verdict

No malicious behavior in our static read, and reputation is strong. Runtime was not executed in a sandbox on this pass, so this is a static-read clearance, not a guarantee.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Cloned npm artifact left-pad@1.3.0
›Verified tarball integrity (sha512)
Static scan
›No flagged regions detected
›No install hooks or obfuscation found
Reputation
›Package age: 12+ years
›High download volume indicates widespread community usage
Read
›README intent matches code functionality
›No undisclosed network or filesystem access
Score
›Score computed by formula: 90/100 (deterministic, code-driven)
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
Auto-published at clauderabbit.in/npm/left-pad · re-checked when the package changes