Extract article content and metadata from web pages.
78%
Total Score
75
94
67
100
Seven contributors were active, but one contributor made 48 of 54 commits, leaving maintenance heavily concentrated despite broader participation.
The project uses TypeScript, webpack, Vitest, and npm scripts, but no security-scanning tools were detected, leaving a modest review gap.
No security policy was found in the repository, which reduces transparency for reporting and handling vulnerabilities.
All 9 action references are unpinned and one release workflow has top-level write permissions. The only audit finding is low-confidence cache-poisoning hygiene, with no untrusted checkout or script-injection paths, so this is a moderate workflow concern rather than a severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-238520 defuddle is vulnerable to Cross-Site Scripting (XSS) in versions 0.9.0 - 0.19.2. | 0.9.0 - 0.19.2 | Medium |
AIKIDO-2026-970758 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. defuddle is vulnerable to Cross-Site Scripting (XSS) in versions 0.15.0 - 0.19.1. | 0.15.0 - 0.19.1 | Medium |
AIKIDO-2026-296759 defuddle is vulnerable to Cross-Site Scripting (XSS) in versions 0.1.0 - 0.19.0. | 0.1.0 - 0.19.0 | High |
CVE-2026-30830 defuddle is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 0.7.0. | 0.0.0 - 0.7.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
commander Version ^12.1.0 | — | — |
mathml-to-latex Version ^1.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.