A Babel preset that enables parsing of proposals supported by the current Node.js version.
68%
Total Score
50
100
88
75
50
No build provenance attestation or trusted-publisher identity is present. This reduces publication transparency, but it is not by itself evidence that the release is unsafe.
One registry account has publish access, which is a limited publishing base. The linked repository is also owned by that user, so the narrow registry list is consistent with direct project ownership rather than unexplained administrative access.
The repository is owned by an individual rather than an organization, so there is no visible organizational backing to offset the small maintainer base. Direct ownership still aligns the source project with the package.
The package has 11 releases since April 2020, but none in the last 12 months; the latest release was about 14 months ago. This indicates a meaningful maintenance slowdown, though the moderate release history provides some maturity.
The repository recorded 0 commits and 0 active maintainers in the last three months. That weakens evidence of active maintenance, although the repository was pushed more recently than the release cadence alone suggests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@babel/plugin-syntax-bigint Version ^7.8.3 | — | — |
@babel/plugin-syntax-import-meta Version ^7.10.4 | — | — |
@babel/plugin-syntax-json-strings Version ^7.8.3 | — | — |
@babel/plugin-syntax-top-level-await Version ^7.14.5 | — | — |
@babel/plugin-syntax-async-generators Version ^7.8.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.