This is a re-bundled version of [Shiki](https://shiki.style) which strips out the dependencies which aren't necessary for [TypeDoc](https://typedoc.org/)'s usage.
65%
Total Score
50
100
67
100
Only one registry account has publish access. This is not conclusive because registry access lists do not measure actual development, but it leaves little publishing redundancy alongside the recent lack of commits.
The repository recorded zero commits and zero active maintainers in the last three months. Regular registry releases partly offset this, but the lack of recent source activity lowers maintenance confidence.
The repository has no security policy. This is a transparency and response-process gap, though it is less serious because the package has provenance and no install lifecycle scripts.
All seven analyzed action references are unpinned, and the publish workflow installs a package outside a lockfile with high confidence; one workflow also grants top-level write access. These are avoidable release-hygiene weaknesses, though no untrusted checkout or script-injection path was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@shikijs/langs Version ^3.23.0 | — | — |
@shikijs/types Version ^3.23.0 | — | — |
@shikijs/themes Version ^3.23.0 | — | — |
@shikijs/vscode-textmate Version ^10.0.2 | — | — |
@shikijs/engine-oniguruma Version ^3.23.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.