Package Health

rehype-raw

rehype plugin to reparse the tree (and raw nodes)

Latest 7.0.0NPMNPM

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher metadata is present, leaving publication provenance less transparent even though this is not evidence of malicious behavior.

Release historycaution

The package has 12 releases since 2016, but none in the last 12 months and its latest release was in August 2023, nearly three years ago. This is a meaningful maintenance concern for a library dependency.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this points to reduced current maintenance capacity.

Repo toolingcaution

The repository uses TypeScript and npm build tooling, but no security scanning tools were detected. This is a modest hygiene gap rather than a severe dependency risk.

Workflow auditcaution

Both workflows were analyzed successfully with no audit findings and no broad top-level write permissions. However, all four action references are unpinned, which weakens reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
vfile
Version ^6.0.0
—
—
@types/hast
Version ^3.0.0
—
—
hast-util-raw
Version ^9.0.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
9 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform