YAML loader for Webpack
68%
Total Score
50
100
81
75
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less transparent, though this is not by itself evidence of an unsafe release.
The repository is owned by an individual rather than an organization, so continuity depends on a relatively small project backing structure.
The package is mature and released version 0.9.0 recently, but it has only one release in the last 12 months and a median interval of about 666 days, indicating a slow cadence.
There were zero commits and zero active maintainers in the last three months. The recent repository push and release provide some compensation, but this remains a meaningful maintenance warning.
The repository has only two open issues and five open pull requests, but no issues or pull requests were opened or closed in the last month, indicating limited recent project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yaml Version ^2.0.0 | — | — |
javascript-stringify Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.