hast utility to transform to mdast
62%
Total Score
75
50
89
83
The package declares 14 runtime dependencies for an HTML-to-Markdown tree transformation. This is a substantial dependency surface but is consistent with the package's broad syntax-handling functionality.
The project has 34 releases over roughly 9 years, but none in the last 12 months despite a latest release in January 2025. This indicates a meaningful maintenance slowdown, though the long release history shows established maturity.
There were no commits and no active maintainers in the last 3 months. Combined with no releases in the last 12 months, this is evidence of currently quiet maintenance.
The repository uses TypeScript and npm build tooling, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of unsafe code.
Both workflows were analyzed successfully and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all four action references are unpinned, leaving the build exposed to moving action revisions; the absence of top-level permissions blocks is not harmful on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@types/hast Version ^3.0.0 | — | — |
@types/mdast Version ^4.0.0 | — | — |
unist-util-visit Version ^5.0.0 | — | — |
hast-util-to-html Version ^9.0.0 | — | — |
hast-util-to-text Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.