Package Health

@mapbox/mapbox-gl-geocoder

A geocoder control for Mapbox GL JS

Latest 5.1.2NPMNPM

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

A prepublish lifecycle script is present, adding some build-time complexity, but this alone is not evidence of poor maintenance or unsafe dependency use.

Release historycaution

The package has 41 releases over nearly ten years, but none in the last twelve months despite a historically regular median interval of about 31 days. This is a meaningful sign of slowing maintenance.

Repo bus factorcaution

All recent repository activity comes from one contributor, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity but does not remove the observed inactivity risk.

Repo commit activitycaution

Only one commit was recorded in the last three months, showing very limited recent development activity and reinforcing the release-history concern.

Repo toolingcaution

The repository uses Babel and npm scripts, but no security scanning tools were detected. Build tooling is established, while security-process coverage is limited.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2025-10597 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@mapbox/mapbox-gl-geocoder is vulnerable to Cross-site Scripting (XSS) in versions 4.0.0 - 5.1.1.
4.0.0 - 5.1.1
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
xtend
Version ^4.0.1
—
—
events
Version ^3.3.0
—
—
nanoid
Version ^3.1.31
—
—
subtag
Version ^0.5.0
—
—
suggestions
Version ^1.6.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
9 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform