Package Health

dompurify

DOMPurify 3.4.15 appears to be a healthy dependency: it has a long release history, frequent recent releases, a stable non-prerelease version, no registry deprecation, a linked active repository, repository tests, strong security and CI tooling, and no runtime dependencies. The main concerns are the absence of build provenance attestation, the install-time prepare script, and highly concentrated recent commit activity, with one contributor responsible for about 94% of commits; however, four active contributors and sustained recent development substantially reduce abandonment risk.

Latest 3.4.15NPMNPM

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build attestation, trusted publisher identity, staged publishing, or approver is reported, reducing release transparency even though other repository and package hygiene signals are strong.

Lifecycle scriptscaution

A prepare lifecycle script is present, which adds install-time execution and some supply-chain surface; no provided evidence shows that this script is dangerous.

Maintainerscaution

Only one registry account, cure53, has publish access, which is a narrow publishing base; repository activity and project evidence provide some compensation, but registry redundancy remains limited.

Repo bus factorcaution

Recent commits are highly concentrated: cure53 made 49 of 52 commits, or about 94%; three additional contributors remained active, which partly mitigates but does not remove the concentration risk.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-904917 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 3.4.3 - 3.4.14.
3.4.3 - 3.4.14
Medium
AIKIDO-2026-514793 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 3.4.14 - 3.4.14.
3.4.14 - 3.4.14
Medium
AIKIDO-2026-404587 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 2.0.0 - 3.4.13.
2.0.0 - 3.4.13
Low
AIKIDO-2026-925458
dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.4.12.
0.0.1 - 3.4.12
Low
AIKIDO-2026-36958
dompurify is vulnerable to Improper Input Validation in versions 3.0.6 - 3.4.10.
3.0.6 - 3.4.10
Low

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
16 days ago
Created
12 years ago
Unpacked Size
1.8 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform