mdast utility to find definition nodes in a tree
62%
Total Score
75
100
89
75
50
No build attestation or trusted-publisher identity is reported, so the release has limited provenance evidence. This is a supply-chain transparency gap, but not a standalone health verdict.
The package has existed for about 11 years with 20 releases, but it has had no release in about 3 years. That long release gap lowers confidence in ongoing maintenance, although the package may be stable.
There were no commits and no active maintainers in the last 3 months, alongside a last push in July 2023. This is strong evidence of stalled maintenance, partly offset by the package's mature, small scope.
The repository uses TypeScript and npm build tooling, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
Both workflows were fully analyzed with no audit findings or untrusted checkouts, and the pull_request_target trigger has no detected sink. However, all 4 action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@types/mdast Version ^4.0.0 | — | — |
@types/unist Version ^3.0.0 | — | — |
unist-util-visit Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.