Package Health

@uiw/codemirror-extensions-basic-setup

Basic configuration for the CodeMirror6 code editor.

Latest 4.25.12NPMNPM

78%

Total Score

healthy

Healthy release with strong packaging and active maintenance, despite a repository mismatch and unpinned workflow actions.

Health Score Breakdown

Repo commit activitycaution

The repository recorded two commits in the last 3 months, so activity is present but relatively light for a project releasing this package frequently.

Repo package mentioncaution

The linked repository name does not match this package and its README does not mention the package, so the package-to-source relationship is not clearly established despite the repository containing a matching extension directory.

Repo toolingcaution

The project uses TypeScript, npm scripts, and ncc, but no security scanning tooling was detected; this is a modest transparency gap rather than a severe concern.

Workflow auditcaution

Both workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings, and one scopes permissions at job level. However, all 11 action references are unpinned, which weakens build reproducibility and supply-chain control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@codemirror/lint
Version ^6.0.0
—
—
@codemirror/view
Version ^6.0.0
—
—
@codemirror/state
Version ^6.0.0
—
—
@codemirror/search
Version ^6.0.0
—
—
@codemirror/commands
Version ^6.0.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
4 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform