100OUT OF 100
TrustedHigh trustStatic read

sindresorhus/p-map

p-map is a highly reputable, widely used utility library for concurrent promise mapping. The static analysis revealed no malicious patterns, network activity, or obfuscation. The code is consistent with its stated purpose as a developer utility. No malicious behavior observed in our static read; full runtime behavior was not executed in a sandbox on this pass.

Repository size
74 KB
Packages
0
Stars
1511
Created
16 yr 9 mo ago
Reputation signals
sindresorhus avatar
Sindre Sorhus
@sindresorhus
Account age16 yr 9 mo
Public repos1.1K
Forks134
Community sentiment100

Excellent

Code & behavior signals
No risky items found

No signatures, install hooks, obfuscation, or embedded secrets were found in the code.

Per-package scoring
Final verdict

No malicious behavior in our static read, and reputation is strong. Runtime was not executed in a sandbox on this pass, so this is a static-read clearance, not a guarantee.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Repository cloned successfully
›Commit: bc8380d3097926eb89c9dc96a94bf0d4ddc4bc03
Static scan
›No flagged regions identified
›No suspicious patterns detected
Reputation
›Owner is a highly trusted, long-standing contributor
›High community adoption
Read
›README intent matches library functionality
›Code structure is clean and standard
Score
›Score computed by formula: 100/100 (deterministic, code-driven)
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+6 [reputation] many_stars: Strong community signal (1,511 stars).
›+4 [reputation] good_sentiment: Positive community sentiment (100/100).
Escalation
›Escalation gate tripped on the static read
›Reason: operator-forced live sandbox verification for this target
›Escalated to a deep behavioural read
Deep read
›This is a highly popular, standard utility library ('p-map') used to map over promises concurrently. It contains no install scripts, no network activity, and no suspicious behaviors.
›No specific harmful behaviour was predicted from the flagged regions.
›Read-only analysis: the code was NOT executed, so run-time-fetched payloads and run-time-built endpoints were not observed.
Auto-published at clauderabbit.in/sindresorhus/p-map · re-checked when the repo changes