Transform class static blocks
15%
Total Score
100
58
83
NPM marks the package deprecated at package scope because the proposal merged into the ECMAScript standard and directs users to @babel/plugin-transform-class-static-block. This makes the release unfit for a new dependency despite the active project behind it.
The package has had no releases in more than three years, with zero releases in the last 12 months. That is consistent with the package being superseded rather than actively maintained.
The linked repository name does not match the package and its README does not mention the package, which is a caution under the package-ownership check. The Babel organization backing and monorepo structure partly explain the mismatch but do not remove the signal entirely.
The audit analyzed all 13 workflows and found no untrusted checkout or script-injection sink, but 119 of 120 action references are unpinned. High-confidence template-injection findings are hygiene concerns here, while the trusted-publishing finding warrants additional caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@babel/helper-plugin-utils Version ^7.20.2 | — | — |
@babel/plugin-syntax-class-static-block Version ^7.14.5 | — | — |
@babel/helper-create-class-features-plugin Version ^7.21.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.