Package Health

fast-xml-parser

Validate XML, Parse XML, Build XML without C/C++ based libraries

Latest 5.11.2NPMNPM

92%

Total Score

healthy

Healthy and actively maintained, with 45 releases in the last year and recent repository activity.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

One contributor made about 82% of recent commits, which concentrates operational knowledge. However, four other contributors were active and the repository is organization-owned, reducing the handoff risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-73569
fast-xml-parser is vulnerable to Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in versions 5.9.3 - 5.10.1.
5.9.3 - 5.10.1
High
AIKIDO-2026-10621 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
fast-xml-parser is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 5.7.1.
4.0.0 - 5.7.1
Medium
CVE-2026-41650
fast-xml-parser is vulnerable to XML Injection (aka Blind XPath Injection) in versions 0.0.0 - 5.7.0.
0.0.0 - 5.7.0
Medium
CVE-2026-33349
fast-xml-parser is vulnerable to Improper Validation of Specified Quantity in Input in versions 4.0.0-beta.3 - 4.5.5 and 5.0.0 - 5.5.7.
4.0.0-beta.3 - 4.5.55.0.0 - 5.5.7
Medium
CVE-2026-33036
fast-xml-parser is vulnerable to Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in versions 5.0.0 - 5.5.6 and 4.0.0-beta.3 - 4.5.5.
4.0.0-beta.3 - 4.5.55.0.0 - 5.5.6
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
strnum
Version ^2.4.2
—
—
is-unsafe
Version ^2.0.0
—
—
xml-naming
Version ^0.3.0
—
—
fast-xml-builder
Version ^1.2.0
—
—
@nodable/entities
Version ^3.0.1
—
—

Weekly Downloads

Info

Last Published
12 days ago
Created
9 years ago
Unpacked Size
1.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform