Package Health

@cspell/cspell-pipe

This is a mature, actively maintained release with 226 releases over roughly 4.6 years, 28 releases in the last 12 months, a current stable major version, and publication as recently as the assessment date. The package is MIT-licensed, includes type declarations, has no runtime dependencies or install lifecycle scripts, and has npm provenance backed by GitHub. Its repository is active, unarchived, organization-owned, well-supported by build and security tooling, and has repository tests and changelog coverage even though those are not packaged. The main transparency concern is that the linked repository neither matches the package name nor mentions it in its README, while a small workflow-permission inconsistency and one pull-request-target workflow warrant routine review; these are modest concerns rather than evidence that the package is unsafe to depend on.

Latest 10.3.0NPMNPM

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 days ago
Created
4 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform