eslint plugin for JSON files
78%
Total Score
50
93
67
All recent commits come from one contributor, leaving maintenance highly dependent on a single person and increasing continuity risk.
One commit was made in the last three months by one active maintainer, showing recent activity but a very thin maintenance cadence.
No build tool or security scanning tool was detected. This is a modest transparency and engineering-hygiene gap, though the repository otherwise contains tests and active release evidence.
The repository has no security policy. This weakens the project's documented process for handling vulnerabilities, but it is not evidence of abandonment by itself.
The workflow audit completed cleanly with no untrusted checkouts, script injection, or audit findings, but all 3 action references are unpinned, leaving them exposed to reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
vscode-json-languageservice Version ^4.1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.