← Rankings

preact

npm · Rank #136 of 217

90 / 100 A
STALE — No release in 35 days. Stale packages accumulate unpatched vulnerabilities.
6
npm publishers
Distributed credential risk
23M
downloads/week
Blast radius if compromised
10.8y
package age
Established package
35 days ago
last release
Active maintenance
35
GitHub contributors
Source code contributors
🔐 Provenance Verified
🛡️ Staged Publishing Enabled
⚠️ Dormant Access 3 inactive publishers with npm access

Risk analysis

preact has not published a release in over 12 months. Stale packages accumulate vulnerabilities and may indicate abandonment.

This package uses staged publishing

Every version goes through a staging area before going live. The maintainer must explicitly approve it with 2FA. This is the strongest protection npm offers against credential theft attacks — even stolen CI tokens can't push code to production.

What the score measures

  • Publisher depth — How many people can push to npm? Single-publisher packages are the #1 structural risk.
  • Longevity — Older packages have track records. New packages with high adoption are higher risk.
  • Release consistency — Regular releases signal active oversight. Long gaps mean unpatched vulnerabilities.
  • Download trend — Growing packages attract more scrutiny (and more attacks).
  • OpenSSF Scorecard — Process security: branch protection, code review, CI/CD safety.
  • Build provenance — Published versions linked to specific CI runs via SLSA attestation.
  • Staged publishing — Human approval gate between npm publish and going live.

preact is one package. Score them all.

You came looking for preact. Your node_modules has hundreds more. Run one command to score every dependency you ship:

npx proof-of-commitment

Auto-detects your lockfile. Scores every dependency. Zero install.

Share this score

Add the badge to your README

Commit trust score for preact
![Commit Trust](https://getcommit.dev/badge/npm/preact)