Package Health

@vercel/fastify

Latest 18.0.1NPMNPM

78%

Total Score

healthy

Active releases and contributors support this package, but the repository mismatch and workflow audit gaps reduce transparency.

Health Score Breakdown

Build provenancecaution

No build attestation or staged publishing evidence was found, leaving release provenance less transparent despite the trusted publisher identity being GitHub.

Repo package mentioncaution

The repository name does not match @vercel/fastify and its README does not mention the package, so the linkage is less transparent even though the repository is owned by the matching Vercel organization.

Type declarationscaution

No type declarations are included, which reduces TypeScript ergonomics for consumers of this library. This is a consumer-experience gap rather than evidence of abandonment.

Workflow auditcaution

All 24 workflows were analyzed, but one file failed audit; 75 of 156 action references are unpinned, and high-confidence template-injection findings plus repeated ad hoc package installs create workflow hygiene concerns. No untrusted checkout or script-injection sink was observed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@vercel/node
Version 23.0.1
—
—
@vercel/static-config
Version 3.4.4
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
11 months ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform