Lightweight, robust, elegant virtual syntax highlighting using Prism
70%
Total Score
50
100
89
75
50
No build attestation or trusted-publisher identity is present. This weakens publication transparency, although it is not by itself evidence that the release is unsafe.
Only one registry account has publish access. That is a thin publishing base and increases continuity risk if that maintainer becomes unavailable.
The package has 42 releases over more than 9 years, but no releases in the last 12 months; the latest release was about 18 months ago. This indicates a mature but currently inactive release cadence.
The repository had zero commits and zero active maintainers in the last 3 months. Combined with the old latest release, this is a meaningful sign of currently limited maintenance.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. This is neutral for a stable package but provides little evidence of current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hastscript Version ^9.0.0 | — | — |
@types/hast Version ^3.0.0 | — | — |
@types/prismjs Version ^1.0.0 | — | — |
parse-entities Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.