A standalone version of the readability library used for Firefox Reader View.
68%
Total Score
67
100
88
100
50
No build attestation or trusted-publisher provenance is present, which leaves publication origin less transparent even though this is a modest supply-chain concern rather than evidence of a bad release.
The package has eight releases since August 2020, but none in the last 12 months and the latest registry release was over a year ago, indicating a notably quiet release cadence.
No commits or active maintainers were recorded in the last three months, which is the strongest maintenance concern despite the repository's recent push timestamp.
There is ongoing issue and pull-request intake, but none of the three pull requests opened in the last month were merged and no issues were closed, suggesting limited recent throughput.
Version 0.6.0 is a stable, non-prerelease release, although the still-pre-1.0 major version leaves more room for compatibility changes than a mature 1.x release.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-2792 @mozilla/readability is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 0.6.0. | 0.0.0 - 0.6.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.