Package Health

org.mvnpm:js-yaml

Healthy and suitable to use. It has frequent recent releases, active source maintenance, licensing, provenance, and safe workflow settings; the main caveat is that recent commits are heavily concentrated in one contributor and repository security tooling is limited.

Latest 5.4.2MavenMaven

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made about 97.6% of the 166 recent commits, creating concentration risk; the organization-owned repository and two additional active contributors partly compensate, but the concentration remains a caveat.

Repo toolingcaution

No build tool or security scanning tool was detected, which is a transparency and maintenance gap, although the repository still has active commits and a security policy.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-480676
js-yaml is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 4.3.0.
3.0.0 - 4.3.0
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
org.mvnpm:argparse
Version [2.0.1,3)

Weekly Downloads

Info

Last Published
10 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform