Package Health

@milkdown/crepe

Latest 7.22.2NPMNPM

88%

Total Score

healthy

Healthy: active releases and a maintained, security-conscious source project support dependable adoption.

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package and its README does not mention @milkdown/crepe, creating some uncertainty about package-to-repository traceability; the organization-owned monorepo context partly explains the mismatch.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-250781 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@milkdown/crepe is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 7.21.0 - 7.21.0.
7.21.0 - 7.21.0
Low

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
vue
Version ^3.5.20
—
—
clsx
Version ^2.0.0
—
—
katex
Version ^0.18.0
—
—
dompurify
Version ^3.2.5
—
—
lodash-es
Version ^4.17.21
—
—

Weekly Downloads

Info

Last Published
14 days ago
Created
2 years ago
Unpacked Size
3.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform