Vite plugin for inlining all JavaScript and CSS resources
78%
Total Score
50
100
94
80
The package uses a prepare install lifecycle script, which adds some build-time supply-chain exposure, although this signal alone is not evidence that the release is unsafe.
The repository is owned by an individual rather than an organization, so there is no organizational succession signal; this is partly offset by the package's established release history and matching repository.
The repository recorded zero commits and zero active maintainers during the last three months, a meaningful maintenance concern. However, the package still has recent registry release activity and was recently pushed, so this is not by itself abandonment.
The repository has only 5 open issues and 2 open pull requests, with one new issue in the last month. There was no recent closure or merge activity, so this provides limited evidence of active maintenance.
The project uses TypeScript, Rollup, Vite, and npm scripts for builds, showing established build tooling, but no security scanning tools were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
micromatch Version ^4.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.