Engine for Shiki using Oniguruma RegExp engine in WebAssembly
87%
Total Score
healthy
Healthy: active releases and an organization-backed repository outweigh workflow and package-ownership hygiene concerns.
The repository name does not match this package and its README does not mention the package, so the package-to-repository link is less directly transparent. The organization-backed monorepo context partly explains the mismatch but does not remove the gap.
The repository has no published security policy, leaving vulnerability-reporting expectations less transparent even though other maintenance evidence is strong.
All 13 action references are unpinned, and the release workflow has top-level write permissions; the audit also found high-severity cache-poisoning with low confidence and repeated high-confidence adhoc-package findings. No untrusted checkout or script-injection paths were found, so this is workflow hygiene rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@shikijs/types Version 4.5.0 | — | — |
@shikijs/vscode-textmate Version ^10.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.