micromark extension to support GFM tables
82%
Total Score
88
100
94
80
50
No build attestation or trusted-publisher provenance is present, leaving release origin less transparent even though other package and repository evidence is healthy.
One of two workflows uses pull_request_target, which can require careful handling of untrusted changes, but no untrusted checkout or script-injection pattern was detected.
The repository had no commits and no active maintainers in the last 3 months, which is a maintenance concern, but the same period includes a current release and recent issue or pull-request activity.
TypeScript and npm build tooling are used, but no repository security-scanning tools were detected; the documented build setup is present while automated security coverage is limited.
Neither workflow declares top-level token permissions, and none declares top-level write access; the omission is less explicit than read-only permissions but does not show excessive access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
devlop Version ^1.0.0 | — | — |
micromark-util-types Version ^2.0.0 | — | — |
micromark-util-symbol Version ^2.0.0 | — | — |
micromark-factory-space Version ^2.0.0 | — | — |
micromark-util-character Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.