mdast extension to parse and serialize frontmatter (YAML, TOML, etc)
68%
Total Score
67
89
83
50
No build attestation or trusted-publisher identity is recorded, reducing publication transparency even though this is not by itself evidence of an unsafe release.
The package has six releases over roughly six years, but none in the last three years; this is meaningful evidence of stagnation for a dependency, despite the stable release history.
There were no commits and no active maintainers in the last three months; together with the old latest release, this indicates inactive maintenance.
There was no issue or pull request activity in the last month and no open work, consistent with a quiet project but not independently severe.
The project uses TypeScript and npm build tooling, but no security scanning tools are reported; this is a modest transparency gap rather than a dependency blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
devlop Version ^1.0.0 | — | — |
@types/mdast Version ^4.0.0 | — | — |
escape-string-regexp Version ^5.0.0 | — | — |
mdast-util-to-markdown Version ^2.0.0 | — | — |
mdast-util-from-markdown Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.