Babel plugin for Vue 2.0 JSX
62%
Total Score
67
100
89
75
50
No build attestation or trusted-publisher provenance is present, which limits publication transparency, but this is a transparency gap rather than evidence that the release is unsafe.
A prepublish lifecycle script adds some install and publication complexity, but the signal does not show a dangerous install-time script.
The package has 9 releases since August 2018, but its latest registry release was in August 2022 and it had no releases in the last 12 months, indicating a long maintenance pause.
The repository had zero commits and zero active maintainers in the last three months, reinforcing the concern that active maintenance has stalled.
There were no new or closed issues or pull requests in the last month, with 41 open issues and 14 open pull requests, suggesting limited recent project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
svg-tags Version ^1.0.0 | — | — |
html-tags Version ^2.0.0 | — | — |
lodash.kebabcase Version ^4.1.1 | — | — |
@babel/plugin-syntax-jsx Version ^7.2.0 | — | — |
@babel/helper-module-imports Version ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.