preact has not published a release in over 12 months. Stale packages accumulate vulnerabilities and may indicate abandonment.
Every version goes through a staging area before going live. The maintainer must explicitly approve it with 2FA. This is the strongest protection npm offers against credential theft attacks — even stolen CI tokens can't push code to production.
npm publish and going live.
You came looking for preact. Your node_modules has hundreds more.
Run one command to score every dependency you ship:
npx proof-of-commitment Auto-detects your lockfile. Scores every dependency. Zero install.
