Package Health

@vue/server-renderer

@vue/server-renderer

Latest 3.5.43NPMNPM

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package name and its README does not mention this package, creating a package-to-repository transparency concern. The organization-owned monorepo context makes a subpackage layout plausible, but the collected signal does not explicitly establish that mapping.

Repo toolingcaution

The project uses established build, test, and compilation tooling, supporting a mature build process; no automated security scanning was detected, which is a modest transparency gap but not severe given the other controls.

Token permissionscaution

Four workflows declare read-only permissions, but the release workflow lacks top-level permissions and four workflows request top-level write access; this leaves some workflow privilege configuration less explicit than ideal.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-283182
@vue/server-renderer is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.5.41.
0.0.1 - 3.5.41
High
AIKIDO-2026-135497
@vue/server-renderer is vulnerable to Cross-Site Scripting (XSS) in versions 3.0.0 - 3.5.39.
3.0.0 - 3.5.39
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@vue/shared
Version 3.5.43
—
—
@vue/runtime-dom
Version 3.5.43
—
—
@vue/compiler-ssr
Version 3.5.43
—
—

Weekly Downloads

Info

Last Published
24 days ago
Created
6 years ago
Unpacked Size
0.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform