IF I put my risk management hat on - 0 days in npm ecosystem are not that much of a problem.
They stop working before can use them.