Vite bundler for Nuxt
96%
Total Score
healthy
Frequent releases, active contributors, and verified publishing make this a mature release; the package is a monorepo subpackage.
The repository name does not match the package and its README does not mention it, creating a package-to-repository transparency concern; the organization-owned Nuxt monorepo context makes a subpackage explanation plausible.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-24360 @nuxt/vite-builder is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 3.8.1 - 3.15.3. | 3.8.1 - 3.15.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ufo Version ^1.6.4 | — | — |
defu Version ^6.1.7 | — | — |
vite Version ^8.3.2 | — | — |
pathe Version ^2.0.3 | — | — |
unenv Version ^2.0.0-rc.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.