Package Health

mdast-util-gfm-table

mdast extension to parse and serialize GFM tables

Latest 2.0.0NPMNPM

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Health Score Breakdown

Build provenancecaution

No build attestation or staged publishing evidence is available, reducing publication transparency, although this does not by itself indicate poor maintenance.

Release historycaution

The package has 16 releases, but the latest registry release was about three years ago and there were no releases in the last 12 months, indicating a significant release gap.

Repo commit activitycaution

No commits or active maintainers were recorded in the last three months, leaving current maintenance activity unclear despite the repository being non-archived.

Repo toolingcaution

The project uses TypeScript and npm build tooling, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.

Workflow auditcaution

Both workflows were analyzed without audit findings, and the pull-request trigger has no untrusted checkout or script-injection sink. However, all four action references are unpinned, leaving avoidable supply-chain hygiene risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
devlop
Version ^1.0.0
—
—
@types/mdast
Version ^4.0.0
—
—
markdown-table
Version ^3.0.0
—
—
mdast-util-to-markdown
Version ^2.0.0
—
—
mdast-util-from-markdown
Version ^2.0.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
6 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform