Unified plugin system for build tools
92%
Total Score
88
100
94
75
100
The repository remains active with new issues and pull requests during the last month, although none were closed or merged in that period. This is a minor process concern but not evidence of abandonment given the recent commits and releases.
The project uses established build and test tools, including TypeScript and Vitest, but no security-scanning tools were detected. The missing security automation is a modest transparency and maintenance gap.
No repository security policy was found. This makes vulnerability reporting less transparent, though active maintenance, organizational backing, and verified provenance compensate for much of the concern.
Two of four workflows lack top-level token permissions, although none declare top-level write access and the analyzed workflows otherwise include read-only permissions. This is a workflow-hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
picomatch Version ^4.0.7 | — | — |
@jridgewell/remapping Version ^2.3.5 | — | — |
webpack-virtual-modules Version ^0.6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.