Package Health

cspell-grammar

Grammar parsing support for cspell

Latest 10.3.6NPMNPM

84%

Total Score

healthy

Healthy release with active maintenance; a high-confidence GitHub Actions credential finding is the main caveat.

Health Score Breakdown

Repo package mentioncaution

The repository name does not match cspell-grammar and its README does not mention the package, creating some uncertainty about package-to-repository ownership despite the apparent monorepo context.

Workflow auditcaution

The audit found a high-confidence, high-severity github-app issue where an app token inherits blanket installation permissions, and only 30 of 37 workflows were analyzed. Pull-request-target triggers had no reported untrusted checkout or script-injection sinks, limiting the overall impact.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@cspell/cspell-pipe
Version 10.3.6
—
—
@cspell/cspell-types
Version 10.3.6
—
—

Weekly Downloads

Info

Last Published
12 days ago
Created
8 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform