Healthy and suitable to adopt. It has a long release history, recent releases, active Apache backing, strong project documentation, and ongoing repository activity. Workflow permissions and concentrated recent commits are the main caveats.
88%
Total Score
90
100
100
80
50
No build attestation or trusted-publisher provenance is present, leaving publication-to-source verification weaker than it could be despite the repository's documented build tooling.
A prepare script runs during installation, adding some install-time behavior that deserves review, although this is not by itself evidence of poor maintenance or abandonment.
One contributor made eight of nine recent commits, creating concentration risk, but a second contributor remains active and the repository is owned by an organization that can hand maintenance off.
Five workflows lack top-level permission declarations and one workflow grants top-level write access, reducing least-privilege transparency even though no dangerous workflow pattern was detected.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-45249 echarts is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 6.1.0. | 0.0.0 - 6.1.0 | Medium |
AIKIDO-2024-10155 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. echarts is vulnerable to Cross-site Scripting in versions 2.2.8 - 5.5.0. | 2.2.8 - 5.5.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
tslib Version 2.3.0 | — | — |
zrender Version 6.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.