recma plugin to add support for parsing and serializing JSX
68%
Total Score
75
50
88
67
50
No build attestation, trusted publisher, or staged publishing is reported, so consumers have less evidence connecting the published artifact to its source build.
One of two workflows uses pull_request_target, which can create elevated workflow risk even though no untrusted checkout or script injection was detected.
The package has 5 runtime dependencies, including parser and transformation components, creating a meaningful dependency surface for consumers but not an unusually large one for this plugin.
The package has only 2 releases over about 699 days, with no releases in the last 12 months and a median interval of about 283 days. This suggests a deliberately slow or inactive release cadence and lowers confidence in ongoing maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the recent release date but still indicating no current development activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
unified Version ^11.0.0 | — | — |
acorn-jsx Version ^5.0.0 | — | — |
recma-parse Version ^1.0.0 | — | — |
recma-stringify Version ^1.0.0 | — | — |
estree-util-to-js Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.