JavaScript library for DOM operations
89%
Total Score
100
94
83
The package publishes no bundled type declarations, which makes integration less convenient for TypeScript consumers; no provided signal shows that this gap is compensated.
All nine workflows were analyzed and all 28 action references are pinned, while eight workflows use read-only permissions. The audit reported a high-severity cache-poisoning pattern with low confidence; because it is low confidence and no untrusted checkout or script injection was found, this is a hygiene concern rather than a severe risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-23064 jquery is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.3 - 3.5.0 and 1.0.3 - 3.5.0. | 1.0.3 - 3.5.0 | Medium |
CVE-2011-4969 jquery is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.6.3 and 0.0.0 - 1.6.3. | 0.0.0 - 1.6.3 | Medium |
CVE-2012-6708 jquery is vulnerable to Windows Shortcut Following (.LNK) in versions 0.0.0 - 1.8.3 and 0.0.0 - 1.8.3. | 0.0.0 - 1.8.3 | Medium |
CVE-2020-11023 jquery is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.3 - 3.5.0 and 1.0.3 - 3.5.0. | 1.0.3 - 3.5.0 | Medium |
CVE-2019-5428 jquery is vulnerable to Security Vulnerability in versions 0.0.0 - 3.4.0 and 0.0.0 - 3.4.0. | 0.0.0 - 3.4.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.