Package Health

@datadog/browser-core

Latest 7.15.0NPMNPM

91%

Total Score

healthy

Healthy release, backed by active organization maintenance; only workflow hygiene and a missing security policy temper confidence.

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

This release has no registry attestation or trusted-publisher provenance, leaving the build-to-published-artifact chain less independently verifiable.

Security policycaution

No repository security policy was found, which reduces the transparency of vulnerability reporting and handling despite the presence of CodeQL and Dependabot tooling.

Workflow auditcaution

All six workflows were analyzed and all 15 action references are pinned, but three workflows grant top-level write permissions and a high-severity cache-poisoning finding was reported with low confidence; the archived action finding is medium severity with high confidence.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-965960 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@datadog/browser-core is vulnerable to Prototype Pollution in versions 1.25.0 - 7.3.0.
1.25.0 - 7.3.0
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@datadog/js-core
Version 0.0.16
—
—

Weekly Downloads

Info

Last Published
12 days ago
Created
6 years ago
Unpacked Size
1.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform