Package Health

@vue/language-core

<

Latest 3.3.13NPMNPM

88%

Total Score

healthy

Frequent releases, active contributors, and build provenance support this release; all workflow actions are unpinned.

Health Score Breakdown

Repo toolingcaution

The project uses TypeScript, Vitest, and npm scripts for builds and tests, but no security-scanning tools were detected, leaving a modest security-process gap.

Security policycaution

No repository security policy was detected, reducing transparency about vulnerability reporting and response expectations.

Workflow auditcaution

All 28 analyzed action references are unpinned, and the audit identifies high-confidence trusted-publishing usage; the workflows have no untrusted checkout or script-injection findings, so this is a hygiene concern rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
picomatch
Version ^4.0.4
—
—
@vue/shared
Version ^3.5.0
—
—
alien-signals
Version ^3.2.1
—
—
muggle-string
Version ^0.4.1
—
—
path-browserify
Version ^1.0.1
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
3 years ago
Unpacked Size
0.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform