This plugin transforms private class methods
12%
Total Score
critical
Unfit to use: the package is deprecated and no longer maintained; use the replacement transform plugin.
The registry marks the package deprecated at package scope because the proposal is now part of ECMAScript and explicitly directs users to @babel/plugin-transform-private-methods. This makes the release unfit for a new dependency despite the active parent project.
The package has had no releases in the last 12 months, with its latest release on April 4, 2023. The long release gap is consistent with the package's stated end of maintenance.
The linked repository name does not match the package and its README does not mention the package, which would normally raise an ownership concern. The matching @babel namespace and Babel organization make a monorepo sub-package explanation plausible, so the concern is limited.
The audit completed all 13 workflows and found no untrusted checkout or script-injection sink, but 119 of 120 action references are unpinned and high-confidence template-injection findings remain. These are secondary workflow hygiene concerns, not the reason to reject this release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@babel/helper-plugin-utils Version ^7.18.6 | — | — |
@babel/helper-create-class-features-plugin Version ^7.18.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.