This is a mature, actively maintained release with strong package hygiene: it has 258 releases over roughly 5 years, 28 releases in the last 12 months, a stable non-prerelease version, bundled type declarations, tests, a changelog, a license file, no install lifecycle scripts, and a matching active source repository. The main concerns are that recent repository activity is concentrated in one contributor, there is no security scanning or security policy, workflows do not declare top-level token permissions, and the package has 25 runtime dependencies with no build provenance attestation. These concerns warrant normal supply-chain review and pinning, but the evidence overall supports depending on the package.
84%
Total Score
70
50
94
80
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-427045 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @amcharts/amcharts5 is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 5.18.0. | 5.0.0 - 5.18.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
d3 Version ^7.0.0 | — | — |
tslib Version ^2.2.0 | — | — |
d3-geo Version ^3.0.0 | — | — |
pdfmake Version ~0.3.9 | — | — |
d3-chord Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.