micromark utility normalize identifiers (as found in references, definitions)
70%
Total Score
63
100
83
88
50
No build attestation or trusted-publisher provenance is present, which limits publication transparency. This is a moderate hygiene gap rather than evidence that the release is unsafe.
Only one registry account has publish access. Organization backing makes a short registry maintainer list less concerning, but it still leaves publishing concentrated.
The package has had no release for about 1 year and 10 months, with no releases in the last 12 months. The linked repository remains active, which partly offsets the stale registry cadence.
All recent commits come from one contributor, creating maintenance concentration. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
The repository recorded 11 commits in the last 3 months, showing ongoing work, but all were made by one active maintainer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
micromark-util-symbol Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.