Streaming HTML parser with scripting support.
68%
Total Score
63
100
94
83
The repository is owned by an individual user rather than an organization, so the single-contributor and bus-factor concerns are not mitigated by explicit organizational backing.
The package is mature, with 8 releases over roughly 8 years, but it had no releases in the last 12 months despite its latest release being in July 2025. This lowers confidence in release cadence.
One contributor made 100% of recent commits, creating a concentrated maintenance dependency without provided organizational backing to offset it.
Six commits were made in the last 3 months, but all came from one active maintainer. The commits show activity, while the narrow recent contributor base adds maintenance risk.
All four workflows were analyzed and all 12 action references are pinned, with no untrusted checkout or script-injection findings. However, a high-confidence bot-conditions finding affects the Dependabot automerge workflow, and one workflow grants top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
parse5 Version ^8.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.