micromark factory to parse labels (found in media, definitions)
68%
Total Score
83
100
81
83
The package has 10 releases since 2021, but none in the last 12 months and the latest release was about 22 months ago. This indicates meaningful release staleness despite a previously regular cadence.
All 11 recent commits came from one contributor, creating concentration risk. However, the repository is owned by an organization, which provides some capacity to hand maintenance off.
The linked repository name does not match the package and its README does not mention it, so the package-to-repository relationship is not transparent even though the repository is a related monorepo-style project.
The project uses TypeScript, Rollup, esbuild, and npm scripts, indicating an established build process. No security-scanning tool was detected, which is a minor hygiene gap.
Both workflows were analyzed without failures, and the pull_request_target trigger has no untrusted checkout or script-injection sink. However, all seven action references are unpinned, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
devlop Version ^1.0.0 | — | — |
micromark-util-types Version ^2.0.0 | — | — |
micromark-util-symbol Version ^2.0.0 | — | — |
micromark-util-character Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.