Package Health

@expo/plist

Mac OS X Plist parser/builder for Node.js and browsers

Latest 0.8.1NPMNPM

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package and its README does not mention @expo/plist, so the package-to-source relationship is less transparent; the name mismatch alone is compatible with a monorepo.

Version stabilitycaution

Version 0.8.1 is a stable release rather than a prerelease, although 70% of recent releases were prereleases, which adds some maturity uncertainty.

Workflow auditcaution

The audit analyzed only 30 of 53 workflows and found high-confidence template-injection patterns plus lower-confidence cache-poisoning and package-install findings. No untrusted checkout or script-injection sink was reported, and the template-injection paths do not match the pull-request-target workflows, limiting the net risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
base64-js
Version ^1.5.1
—
—
xmlbuilder
Version ^15.1.1
—
—
@xmldom/xmldom
Version ^0.8.8
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
6 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform