Lezer-based YAML grammar
35%
Total Score
75
100
88
75
50
The linked repository is archived even though it was pushed recently, so new fixes and maintenance are not dependable. This is a severe adoption risk for a package developers must maintain over time.
No build attestation, trusted publisher, or staged publishing evidence is present. This weakens publication transparency but is not independently severe.
A prepare script runs during package installation or publication. This is a mild operational consideration, but the provided signals do not show harmful behavior.
There were no commits and no active maintainers in the last three months, consistent with the repository's archived state. This reduces confidence that defects will be addressed.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, though it does not by itself show abandonment or unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@lezer/lr Version ^1.4.0 | — | — |
@lezer/common Version ^1.2.0 | — | — |
@lezer/highlight Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.