DOMPurify 3.4.15 appears to be a healthy dependency: it has a long release history, frequent recent releases, a stable non-prerelease version, no registry deprecation, a linked active repository, repository tests, strong security and CI tooling, and no runtime dependencies. The main concerns are the absence of build provenance attestation, the install-time prepare script, and highly concentrated recent commit activity, with one contributor responsible for about 94% of commits; however, four active contributors and sustained recent development substantially reduce abandonment risk.
91%
Total Score
80
100
100
90
50
No build attestation, trusted publisher identity, staged publishing, or approver is reported, reducing release transparency even though other repository and package hygiene signals are strong.
A prepare lifecycle script is present, which adds install-time execution and some supply-chain surface; no provided evidence shows that this script is dangerous.
Only one registry account, cure53, has publish access, which is a narrow publishing base; repository activity and project evidence provide some compensation, but registry redundancy remains limited.
Recent commits are highly concentrated: cure53 made 49 of 52 commits, or about 94%; three additional contributors remained active, which partly mitigates but does not remove the concentration risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-904917 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 3.4.3 - 3.4.14. | 3.4.3 - 3.4.14 | Medium |
AIKIDO-2026-514793 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 3.4.14 - 3.4.14. | 3.4.14 - 3.4.14 | Medium |
AIKIDO-2026-404587 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 2.0.0 - 3.4.13. | 2.0.0 - 3.4.13 | Low |
AIKIDO-2026-925458 dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.4.12. | 0.0.1 - 3.4.12 | Low |
AIKIDO-2026-36958 dompurify is vulnerable to Improper Input Validation in versions 3.0.6 - 3.4.10. | 3.0.6 - 3.4.10 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.