remark plugin to support GFM (autolink literals, footnotes, strikethrough, tables, tasklists)
72%
Total Score
88
100
90
80
50
No registry build attestation or trusted-publisher identity is present, reducing publication transparency, but this is a supply-chain transparency gap rather than evidence that the release is unsafe.
One of two workflows uses pull_request_target, which warrants workflow review, but there are no untrusted checkouts or script-injection findings.
Six releases over about six years with the latest released about 19 months before collection indicates a deliberately sparse cadence, but not abandonment by itself for a mature plugin.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with roughly 19 months since the latest push; this is the main abandonment concern.
TypeScript and npm build tooling are present, but no security-scanning tools were detected, leaving a modest security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
unified Version ^11.0.0 | — | — |
@types/mdast Version ^4.0.0 | — | — |
remark-parse Version ^11.0.0 | — | — |
mdast-util-gfm Version ^3.0.0 | — | — |
remark-stringify Version ^11.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.