mdast utility to serialize markdown
88%
Total Score
healthy
Healthy: active organization-backed maintenance and a recent release outweigh minor workflow pinning gaps.
No build attestation or trusted-publisher provenance is recorded, leaving publication origin less independently verifiable despite the package's otherwise healthy maintenance evidence.
The project uses TypeScript and npm build tooling, but no repository security-scanning tool was detected. This is a modest transparency and hygiene gap, not evidence of abandonment.
Both workflows were analyzed without failed files or dangerous findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all four action references are unpinned, which weakens reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zwitch Version ^2.0.0 | — | — |
@types/mdast Version ^4.0.0 | — | — |
@types/unist Version ^3.0.0 | — | — |
longest-streak Version ^3.0.0 | — | — |
unist-util-visit Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.