Package Health

@cloudflare/vitest-pool-workers

Workers Vitest integration for writing Vitest unit and integration tests that run inside the Workers runtime

Latest 0.23.0NPMNPM

28%

Total Score

unhealthy

This release is explicitly discontinued, with a replacement available, despite strong maintenance in its source repository.

Health Score Breakdown

Package scaffoldingdanger

The package includes a README, while the source repository has tests and a changelog. However, the README explicitly says this package was renamed and will receive no future updates, with `@cloudflare/vitest-plugin` as the replacement.

Licensecaution

The package declares MIT, but the linked repository license file was detected as Apache-2.0, leaving licensing terms unclear for consumers.

Registry deprecationcaution

The registry does not mark the package as deprecated, but the published README independently states that the package is discontinued; the explicit package guidance is more consequential for adoption.

Repo package mentioncaution

The linked repository is an organization monorepo whose name does not match the package, and its README does not mention the package. The mismatch is plausible for a subpackage, but the missing README mention leaves some package-to-repository transparency uncertainty.

Workflow auditcaution

All 28 workflows were analyzed with no failed files and all 65 action references pinned. The audit found a medium-confidence high-severity bot-condition issue and two high-confidence adhoc package installations; untrusted checkouts and several write-scoped workflows add caution, though no script injection was detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
zod
Version 4.4.3
—
—
esbuild
Version 0.28.1
—
—
wrangler
Version 4.124.0
—
—
miniflare
Version 5.20260815.0-alpha
—
—
cjs-module-lexer
Version 1.2.3
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
2 years ago
Unpacked Size
7.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform