This plugin generates [Vercel Build Output API v3](https://vercel.com/docs/build-output-api/v3) for Gatsby v4+ projects.
82%
Total Score
healthy
Frequent stable releases and active Vercel backing outweigh repository-link ambiguity and workflow hygiene findings.
No build attestation is present, so published-build traceability is limited. The trusted publisher ID is GitHub, which provides some publishing context but does not replace an attestation.
The linked repository name does not match the package and its README does not mention the package. This is plausible for a monorepo subpackage, but the missing explicit mention leaves package-to-repository linkage less transparent.
No type declarations are published. This is a modest consumer-ergonomics gap for a Gatsby plugin, but it does not indicate abandonment or unclear ownership.
All 24 workflows were analyzed, but one file failed and 75 of 156 action references are unpinned. High-confidence template-injection findings and broad workflow hygiene issues merit caution, although no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
etag Version 1.8.1 | — | — |
esbuild Version 0.27.0 | — | — |
fs-extra Version 11.1.0 | — | — |
@sinclair/typebox Version 0.25.24 | — | — |
@vercel/build-utils Version 14.20.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.