A geocoder control for Mapbox GL JS
62%
Total Score
67
88
67
A prepublish lifecycle script is present, adding some build-time complexity, but this alone is not evidence of poor maintenance or unsafe dependency use.
The package has 41 releases over nearly ten years, but none in the last twelve months despite a historically regular median interval of about 31 days. This is a meaningful sign of slowing maintenance.
All recent repository activity comes from one contributor, creating a concentrated maintenance dependency. Organization backing provides some handoff capacity but does not remove the observed inactivity risk.
Only one commit was recorded in the last three months, showing very limited recent development activity and reinforcing the release-history concern.
The repository uses Babel and npm scripts, but no security scanning tools were detected. Build tooling is established, while security-process coverage is limited.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10597 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @mapbox/mapbox-gl-geocoder is vulnerable to Cross-site Scripting (XSS) in versions 4.0.0 - 5.1.1. | 4.0.0 - 5.1.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
xtend Version ^4.0.1 | — | — |
events Version ^3.3.0 | — | — |
nanoid Version ^3.1.31 | — | — |
subtag Version ^0.5.0 | — | — |
suggestions Version ^1.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.