Highlight Single-File Components of Vue.js Framework
35%
Total Score
50
100
58
100
The package resembles highlight.js, has 21,296,447 monthly downloads versus 123,479,958, and explicitly borrows its identity; the README also identifies it with the lookalike, making this a severe consumer-confusion risk despite zero artifact overlap.
The package is about 6 years and 10 months old but has only two releases, both concentrated on the first day, with no releases in the last 12 months. This strongly suggests the release line is abandoned.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the lack of recent registry releases and lowering confidence in ongoing maintenance.
The manifest declares CC0-1.0 while the repository license file is detected as BSD-3-Clause. The repository is licensed, but the mismatch creates avoidable uncertainty about the terms covering this package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.