Dependency health Workspace

left-padnpm

Documented supply-chain history

This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.

Read the incident coverage →
What the project says about itself
  • Build provenance — the latest release carries no provenance attestation. Source: the registry.
  • Publishers on the registry — 2. Source: the registry.
  • OpenSSF Scorecard3.9 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-05 first verdict: dead
Supply-chain history 1
  1. pulled from the registry 2016-03

    Unpublished by its author during a naming dispute, breaking builds across the ecosystem.

    npm restored it and changed the unpublish rules because of it.

    Source: npm post-mortem, March 2016. History, not a warning about today — the verdict above is about maintenance now.

Where to go instead 1
  1. String.prototype.padStart Drop-in replacement

    Standard since ES2017 — this needs no dependency at all

    `leftPad(s, n, c)` becomes `s.padStart(n, c)`.

    Checked by hand.

Badge

maintenance: dead

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/npm/left-pad.svg)](https://isitdeadyet.dev/npm/left-pad)

Watch it

Get told when left-pad changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.