Gathering detailed insights and metrics for @jolduca/rehype-slug
Gathering detailed insights and metrics for @jolduca/rehype-slug
Gathering detailed insights and metrics for @jolduca/rehype-slug
Gathering detailed insights and metrics for @jolduca/rehype-slug
npm install @jolduca/rehype-slug
Typescript
Module System
Node Version
NPM Version
21.3
Supply Chain
98.6
Quality
74.8
Maintenance
100
Vulnerability
100
License
JavaScript (100%)
Total Downloads
0
Last Day
0
Last Week
0
Last Month
0
Last Year
0
MIT License
223 Stars
97 Commits
10 Forks
7 Watchers
1 Branches
10 Contributors
Updated on Jul 06, 2025
Latest Version
5.0.2
Package Id
@jolduca/rehype-slug@5.0.2
Unpacked Size
10.54 kB
Size
4.36 kB
File Count
5
NPM Version
7.7.6
Node Version
15.14.0
Cumulative downloads
Total Downloads
Last Day
0%
NaN
Compared to previous day
Last Week
0%
NaN
Compared to previous week
Last Month
0%
NaN
Compared to previous month
Last Year
0%
NaN
Compared to previous year
rehype plugin to add id
s to headings.
This package is a unified (rehype) plugin to add id
s to headings.
It looks for headings (so <h1>
through <h6>
) that do not yet have id
s
and adds id
attributes to them based on the text they contain.
The algorithm that does this is github-slugger
, which
matches how GitHub works.
unified is a project that transforms content with abstract syntax trees
(ASTs).
rehype adds support for HTML to unified.
hast is the HTML AST that rehype uses.
This is a rehype plugin that adds id
s to headings in the AST.
This plugin is useful when you have relatively long documents and you want to be able to link to particular sections.
A different plugin, rehype-autolink-headings
, adds
links to these headings back to themselves, which is useful as it lets users
more easily link to particular sections.
This package is ESM only. In Node.js (version 12.20+, 14.14+, or 16.0+), install with npm:
1npm install rehype-slug
In Deno with esm.sh
:
1import rehypeSlug from 'https://esm.sh/rehype-slug@5'
In browsers with esm.sh
:
1<script type="module"> 2 import rehypeSlug from 'https://esm.sh/rehype-slug@5?bundle' 3</script>
Say we have the following file example.html
:
1<h1 id=some-id>Lorem ipsum</h1> 2<h2>Dolor sit amet 😪</h2> 3<h3>consectetur & adipisicing</h3> 4<h4>elit</h4> 5<h5>elit</h5>
And our module example.js
looks as follows:
1import {read} from 'to-vfile' 2import {rehype} from 'rehype' 3import rehypeSlug from 'rehype-slug' 4 5main() 6 7async function main() { 8 const file = await rehype() 9 .data('settings', {fragment: true}) 10 .use(rehypeSlug) 11 .process(await read('example.html')) 12 13 console.log(String(file)) 14}
Now, running node example.js
yields:
1<h1 id="some-id">Lorem ipsum</h1> 2<h2 id="dolor-sit-amet-">Dolor sit amet 😪</h2> 3<h3 id="consectetur--adipisicing">consectetur & adipisicing</h3> 4<h4 id="elit">elit</h4> 5<h5 id="elit-1">elit</h5>
This package exports no identifiers.
The default export is rehypeSlug
.
unified().use(rehypeSlug)
Add id
s to headings.
There are no options.
This package is fully typed with TypeScript. There are no extra exported types.
Projects maintained by the unified collective are compatible with all maintained versions of Node.js. As of now, that is Node.js 12.20+, 14.14+, and 16.0+. Our projects sometimes work with older versions, but this is not guaranteed.
This plugin works with rehype-parse
version 1+, rehype-stringify
version 1+,
rehype
version 1+, and unified
version 4+.
Use of rehype-slug
can open you up to a cross-site scripting (XSS)
attack as it sets id
attributes on headings, which causes what is known
as “DOM clobbering”.
Please use rehype-sanitize
and see its
Example: headings (DOM clobbering) for information on
how to properly solve it.
rehype-autolink-headings
— add links to headings with IDs back to themselvesSee contributing.md
in rehypejs/.github
for ways
to get started.
See support.md
for ways to get help.
This project has a code of conduct. By interacting with this repository, organization, or community you agree to abide by its terms.
No vulnerabilities found.
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
0 existing vulnerabilities detected
Reason
license file detected
Details
Reason
security policy file detected
Details
Reason
0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
Reason
Found 2/30 approved changesets -- score normalized to 0
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
project is not fuzzed
Details
Reason
Project has not signed or included provenance with any releases.
Details
Reason
branch protection not enabled on development/release branches
Details
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Score
Last Scanned on 2025-07-07
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More