Package Health

@ui5/webcomponents-base

UI5 Web Components: webcomponents.base

Latest 2.27.2NPMNPM

84%

Total Score

healthy

Healthy, with workflow permission and script-injection concerns that warrant review before relying on releases.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

All 14 workflows were analyzed, but the audit found one script-injection issue, broad app-token permissions, and 49 of 56 action references unpinned. These are meaningful release-automation hygiene concerns, though no untrusted checkout or dangerous trigger was reported.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-760121 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@ui5/webcomponents-base is vulnerable to Origin Validation Error in versions 1.12.0 - 2.21.1.
1.12.0 - 2.21.1
Low
AIKIDO-2026-707978 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@ui5/webcomponents-base is vulnerable to Inclusion of Functionality from Untrusted Control Sphere in versions 1.12.0 - 2.17.1.
1.12.0 - 2.17.1
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
lit-html
Version ^2.0.1
—
—
@lit-labs/ssr-dom-shim
Version ^1.1.2
—
—

Weekly Downloads

Info

Last Published
12 days ago
Created
7 years ago
Unpacked Size
3.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform