Track Core Web Vitals in Gatsby projects with Vercel Speed Insights.
72%
Total Score
90
100
90
88
50
The package has no build attestation, so publication cannot be independently verified from the provided provenance data. The trusted publisher is identified as GitHub, which partly offsets this transparency gap.
The repository remains active, with 20 new issues and 39 new pull requests in the last month, although only 3 issues and 2 pull requests were closed or merged. The workload is a mild maintenance concern but not abandonment evidence.
The linked repository name does not match the package and its README does not mention the package, so the source-package relationship is not established by this signal. Organizational ownership and the package README provide context but do not remove that uncertainty.
The package provides no type declarations. That is a minor integration gap for a Gatsby plugin, but it does not by itself indicate abandonment or unsafe maintenance.
All but one workflow was analyzed, but one file failed audit. High-confidence template-injection findings and numerous ad hoc package installs warrant workflow hygiene caution; no untrusted checkout or script-injection sink was found, and only 75 of 156 action uses were unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
web-vitals Version 0.2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.