@wordpress/i18n
WordPress internationalization (i18n) library.
27
Versions
GPL-2.0-or-later
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
garypendergastadamsilversteingziolontwbriadnoisysockskadamwhitegutenbergpluginjorgefilipecostaellatrixiandunn206whyisjakeockhamsirrealnosoloswwpisabelntsekourasnerraddesrosjtalldanwppeterwilsonccryanwelchermamaduka
Keywords
wordpressgutenbergi18n
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | suspicious-version-number | AI (publish-pattern): Version pattern is legitimate Gutenberg pre-release versioning, not a malware indicator. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects legitimate feature expansion (tannin integration) and new dependencies, not injected payloads. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer additions reflect Gutenberg team structure; no compromise indicators. | ai | |
| phantom-deps | phantom-dep:@wordpress/deprecated | AI (phantom-deps): Same-org dependency declared in package.json; common pattern in WordPress monorepo packages. | ai | |
| dependencies | unvetted-dep:jed | AI (dependencies): jed is a well-known gettext/i18n JavaScript library; its use is appropriate and expected for a WordPress i18n package. Stable across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance attestation; established WordPress org package with 239 versions and clean history. No provenance is expected for this era. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher transition (riad → gutenbergplugin) occurred 1.5+ years ago; aligns with Gutenberg org structure. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dependencies (sprintf-js, tannin) are small, focused libraries appropriate for i18n functionality; represents expected maintenance, not attack pattern. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Single maintainer removal in context of 8 additions reflects normal team transitions in established projects. | ai | |
| dependencies | unvetted-dep:sprintf-js | AI (dependencies): sprintf-js is a well-known string formatting library and a natural, expected dependency for an i18n package. No malicious signals; stable for this package. | ai | |
| dependencies | unvetted-dep:gettext-parser | AI (dependencies): gettext-parser is a standard i18n parsing library; appropriate for WordPress i18n package. | ai | |
| dependencies | unvetted-dep:tannin | AI (dependencies): tannin is a legitimate i18n library; stable dependency for this package's use case. | ai | |
| phantom-deps | phantom-dep:memize | AI (phantom-deps): memize is a legitimate caching utility used in WordPress packages; phantom status is benign. | ai | |
| license | copyleft-license:GPL-2.0-or-later | AI (license): GPL-2.0-or-later is the standard license for all WordPress ecosystem packages; this is intentional and not a security concern. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 6.19.0 | 5 / 1 | |
| 6.18.0 | 5 / 1 | |
| 5.12.0 | 6 / 0 | |
| 5.7.0 | 6 / 0 | |
| 5.4.0 | 6 / 0 | |
| 5.3.0 | 6 / 0 | |
| 4.45.0 | 6 / 0 | |
| 4.42.9 | 6 / 0 | |
| 4.22.0 | 6 / 0 | |
| 4.12.0 | 7 / 0 | |
| 4.2.2 | 7 / 0 | |
| 3.20.0 | 7 / 0 | |
| 3.15.0 | 6 / 0 | |
| 3.6.0 | 6 / 0 | |
| 3.4.0 | 6 / 0 | |
| 3.2.0 | 6 / 0 | |
| 3.1.0 | 6 / 1 | |
| 3.0.1 | 5 / 1 | |
| 3.0.0 | 6 / 1 | |
| 2.0.0 | 5 / 1 | |
| 1.2.3 | 5 / 1 | |
| 1.2.2 | 5 / 1 | |
| 1.2.1 | 5 / 1 | |
| 1.2.0 | 4 / 1 | |
| 1.1.1 | 4 / 0 | |
| 1.1.0 | 4 / 0 | |
| 1.0.0 | 4 / 0 |