Package Health

@parcel/package-manager

Blazing fast, zero configuration web application bundler

Latest 2.16.4NPMNPM

58%

Total Score

caution

Usable with caveats: no repository commits in the last three months and all 49 workflow actions are unpinned.

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last three months, a significant recent-maintenance warning. The package’s release history and recent repository push provide some counterweight but do not remove the concern.

Workflow auditdanger

All six workflows were analyzed without failures and no untrusted checkouts or script-injection sinks were found. However, all 49 action references are unpinned, and high-confidence template-injection and secrets-inherit findings weaken release-workflow hygiene; the low-confidence cache findings add little weight.

Build provenancecaution

No build attestation or trusted-publisher provenance is present, leaving publication origin less independently verifiable. This is a transparency weakness, not evidence that the release is unsafe.

Dependency profilecaution

Nine runtime dependencies, including several related Parcel packages and build tooling, create a meaningful dependency surface. The profile is coherent for a package-manager component but increases transitive maintenance exposure.

Repo issue activitycaution

Issues and pull requests remain active, with new issues and pull requests in the last month, but no pull requests were merged during that period. This supports ongoing attention while showing limited recent throughput.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
semver
Version ^7.7.1
—
—
@swc/core
Version ^1.11.24
—
—
@parcel/fs
Version 2.16.4
—
—
@parcel/types
Version 2.16.4
—
—
@parcel/utils
Version 2.16.4
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
6 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform