left-padnpm
This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.
Read the incident coverage →- latest 1.3.0
- licence WTFPL
- stars 1,305
- checked today
- registry ↗
- repository ↗
Maintenance trends
Loading historical repository activity…
Signals · last 2 checks
What the project says about itself
- Build provenance — the latest release carries no provenance attestation. Source: the registry.
- Publishers on the registry — 2. Source: the registry.
- OpenSSF Scorecard — 3.9 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.
Third-party facts checked today; registry facts on every crawl.
State history 1
| When | Change |
|---|---|
| 2026-09-05 | first verdict: dead |
Supply-chain history 1
-
pulled from the registry 2016-03
Unpublished by its author during a naming dispute, breaking builds across the ecosystem.
npm restored it and changed the unpublish rules because of it.
Source: npm post-mortem, March 2016. History, not a warning about today — the verdict above is about maintenance now.
Where to go instead 1
-
String.prototype.padStart Drop-in replacement
Standard since ES2017 — this needs no dependency at all
`leftPad(s, n, c)` becomes `s.padStart(n, c)`.
Checked by hand.
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/npm/left-pad)
Watch it
Get told when left-pad changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.