Is rc healthy, maintained, and safe?
No — rc carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
The verdict
OSPulse scores rc at 18/100 (critical risk), computed deterministically from live npm release history, maintainer data, and the OSV vulnerability database. No — rc carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
The last sign of life was 4 November 2021, more than 4 years ago (1726 days); by any practical measure the package looks abandoned. Historically it released far more frequently, so the current silence reads as a genuine collapse in velocity rather than a natural gap. 9 maintainers are listed on npm, so the project isn't hostage to any single contributor.
OSV lists 1 known advisory for rc, including 1 critical. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.
The safest reading is to replace, fork, or tightly pin rc and stop taking on new exposure to it. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own package.json through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (1)
- GHSA-g2q5-5433-rhrf ↗CRITICAL
Embedded malware in rc
Key facts
- Latest version
- v1.2.8
- Last release
- 4 November 2021 (1726 days ago)
- Total releases
- 51
- First release
- 5 August 2012
- Package age
- 14.0 years
- Maintainers
- 9
- Known advisories
- 1
- Confidence
- High
Frequently asked
Is rc still maintained?
It doesn't appear to be — the last release was 4 November 2021, over two years ago, which usually indicates an abandoned package.
Does rc have known security vulnerabilities?
Yes — OSV lists 1 advisory for rc, including 1 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.
Is rc safe to use?
No — rc carries 1 unpatched critical advisory and should not be adopted without a remediation plan. OSPulse rates it 18/100 (critical risk) based on release recency, cadence, maintainer bus factor and known vulnerabilities.
Other npm packages we've checked
rc is one package. What about the other hundreds in your tree?
Paste your own package.json into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the npm registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
