`rrdom` is a virtual dom library that is used by `rrweb` to replay DOM mutations. It is a standalone library that can be used to create a virtual dom tree and apply patches to the real dom. It's used in `rrweb` to optimize replay performance especially wh
84%
Total Score
100
100
94
50
100
A prepublish lifecycle script is present. This is a limited packaging automation concern, but the release also has build provenance and the script is not evidence of poor maintenance by itself.
The repository name differs from the package name and its README does not mention @amplitude/rrdom. A monorepo mismatch alone is ordinary, but the absence of a package mention creates some uncertainty about repository linkage.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear. This is a transparency gap, not evidence of abandonment.
All six workflows were analyzed, all 22 action references are pinned, and no untrusted checkout or script-injection paths were found. One high-confidence low-severity finding reports an ad hoc package install in the release workflow, so workflow hygiene is slightly weaker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@amplitude/rrweb-snapshot Version ^2.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.