Package Health

@rspack/core

This release appears to be a healthy, mature dependency with strong ongoing maintenance and release transparency. It has been released 1,235 times over more than four years, with 78 releases in the last 12 months, the repository was pushed very recently and is not archived, and repository activity is substantial across 30 active maintainers. The package has MIT licensing, extensive type declarations, npm provenance, no install-time lifecycle scripts, a security policy, and active issue and pull-request throughput. The main reservations are that the artifact omits tests and a changelog, although repository tests and GitHub Releases provide meaningful compensation, and many workflows lack explicit top-level permissions or use write permissions, which is a repository hygiene concern rather than evidence that the package is unsafe to depend on.

Latest 2.2.3NPMNPM

94%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2024-10552 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@rspack/core is vulnerable to Malicious Code in versions 1.1.7 - 1.1.7.
1.1.7 - 1.1.7
Critical

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@rspack/binding
Version 2.2.3

Weekly Downloads

Info

Last Published
4 days ago
Created
4 years ago
Unpacked Size
1.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform