Package Health

hast-util-sanitize

hast utility to sanitize nodes

Latest 5.0.2NPMNPM

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is present, leaving publication origin less verifiable than it could be. This is a transparency gap but not evidence of a bad release.

Release historycaution

The package has 20 releases over more than 10 years, but no releases in the last 12 months and its latest release was nearly two years ago. This points to reduced maintenance activity, though the long release history shows maturity.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months, reinforcing the sign that maintenance has slowed substantially.

Repo toolingcaution

The repository uses TypeScript and npm scripts, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap, partly offset by the separate security policy.

Workflow auditcaution

Both workflows were fully analyzed with no audit findings or untrusted checkouts, but all 4 action references are unpinned. One pull_request_target trigger is ordinary and has no reported dangerous sink.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@types/hast
Version ^3.0.0
—
—
unist-util-position
Version ^5.0.0
—
—
@ungap/structured-clone
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
10 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform