Healthy and suitable to depend on. It has a long release history, a recent release, active repository work, tests, changelog, security tooling, and signed Maven provenance; maintenance is concentrated primarily in one contributor.
88%
Total Score
80
100
100
90
100
The package maps to a matching repository owned by a user rather than an organization. That is compatible with the observed active maintenance, though it provides less institutional handoff capacity.
Maintenance is highly concentrated: one contributor made 66 of 67 recent commits, despite a second contributor remaining active. This leaves a meaningful continuity risk for a user-owned project.
All 3 workflows lack top-level permissions declarations, which is a workflow-hardening gap; none declares top-level write access, so the risk is limited rather than severe.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-499637 jsoup is vulnerable to Cross-Site Scripting (XSS) in versions 1.14.3 - 1.22.2. | 1.14.3 - 1.22.2 | Medium |
AIKIDO-2025-10401 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. jsoup is vulnerable to Cross-site Scripting (XSS) in versions 1.12.2 - 1.21.0. | 1.12.2 - 1.21.0 | Medium |
CVE-2022-36033 org.jsoup:jsoup is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.15.3. | 0.0.0 - 1.15.3 | Medium |
CVE-2015-6748 org.jsoup:jsoup is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.6.0 - 1.8.2. | 1.6.0 - 1.8.2 | Medium |
CVE-2021-37714 org.jsoup:jsoup is vulnerable to Uncaught Exception in versions 0.0.0 - 1.14.2. | 0.0.0 - 1.14.2 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
com.google.re2j:re2j Version 1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.