The official [Svelte](https://svelte.dev) plugin for [Vite](https://vitejs.dev).
86%
Total Score
healthy
Healthy: active organization-backed maintenance and reproducible publishing outweigh a few CI workflow hygiene issues.
Both workflows were analyzed, use read-only permissions, and have no untrusted checkout or script-injection findings; all 11 action references are pinned. However, five high-confidence unsound-condition findings and three high-confidence adhoc-packages findings indicate CI logic and dependency-installation hygiene issues, so this is a modest concern rather than a release-blocking risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
obug Version ^2.1.0 | — | — |
vitefu Version ^1.1.2 | — | — |
deepmerge Version ^4.3.1 | — | — |
magic-string Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.