Generic JSDoc-like comment parser
88%
Total Score
88
100
94
70
50
No build attestation, trusted publisher identity, or staged publishing is reported, leaving the correspondence between repository source and the published artifact less independently verifiable.
A prepare install-time lifecycle script is present, which adds some execution surface during installation; the available workflow and repository evidence shows no dangerous workflow patterns, but does not eliminate the extra lifecycle risk.
The repository is owned by an individual user rather than an organization, so the one registry maintainer is not compensated by visible organization-level ownership; recent activity from two contributors nevertheless provides some practical continuity.
The repository uses TypeScript, Rollup, and npm scripts for builds, but reports no security-scanning tools; this is a transparency and defense-in-depth gap rather than evidence of abandonment.
No SECURITY.md or equivalent security policy is present, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.