Package Health

@amcharts/amcharts5

This is a mature, actively maintained release with strong package hygiene: it has 258 releases over roughly 5 years, 28 releases in the last 12 months, a stable non-prerelease version, bundled type declarations, tests, a changelog, a license file, no install lifecycle scripts, and a matching active source repository. The main concerns are that recent repository activity is concentrated in one contributor, there is no security scanning or security policy, workflows do not declare top-level token permissions, and the package has 25 runtime dependencies with no build provenance attestation. These concerns warrant normal supply-chain review and pinning, but the evidence overall supports depending on the package.

Latest 5.20.5NPMNPM

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-427045 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@amcharts/amcharts5 is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 5.18.0.
5.0.0 - 5.18.0
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
d3
Version ^7.0.0
tslib
Version ^2.2.0
d3-geo
Version ^3.0.0
pdfmake
Version ~0.3.9
d3-chord
Version ^3.0.0

Weekly Downloads

Info

Last Published
12 days ago
Created
5 years ago
Unpacked Size
25.6 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform