hast utility to transform to preact, react, solid, svelte, vue, etc
67%
Total Score
83
90
83
50
No build attestation or trusted-publisher provenance was recorded. This reduces publication transparency, though the package has a matching source repository, license, and documented build tooling.
The package has 15 releases over about three years with a typical interval of 12 days, but it has had no release in the last 12 months. This is a meaningful maintenance concern despite the previously regular cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This is the strongest abandonment concern, although the package may be stable and the repository is not archived.
The project uses TypeScript, esbuild, and npm scripts, showing an established build process, but no security-scanning tools were detected. The tooling is otherwise appropriate for the package.
Both workflows were fully analyzed with no detected findings or untrusted checkouts, and no workflow has top-level write permissions. However, all four action references are unpinned, leaving avoidable build-reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
devlop Version ^1.0.0 | — | — |
@types/hast Version ^3.0.0 | — | — |
style-to-js Version ^1.0.0 | — | — |
@types/unist Version ^3.0.0 | — | — |
@types/estree Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.