A JavaScript Chart Library
84%
Total Score
healthy
Active releases and a well-backed repository outweigh concentrated commits and workflow hygiene gaps.
Although 12 maintainers contributed recently, one contributor made about 89% of the 535 commits, leaving meaningful dependence on a single individual. Organization backing partly reduces handoff risk.
No SECURITY.md policy was found. This is a transparency gap for reporting vulnerabilities, although active development and CodeQL scanning provide some compensation.
All 8 workflows were analyzed without untrusted checkouts or script injection, but all 19 action references are unpinned, one publish workflow has top-level write permissions, and a high-confidence audit found adhoc package installation. These are workflow hygiene concerns, not severe evidence on their own.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-23327 apexcharts is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.24.0. | 0.0.0 - 3.24.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
apex-commons Version ^0.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.