Package Health

jquery

JavaScript library for DOM operations

Latest 4.0.0NPMNPM

89%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Type declarationscaution

The package publishes no bundled type declarations, which makes integration less convenient for TypeScript consumers; no provided signal shows that this gap is compensated.

Workflow auditcaution

All nine workflows were analyzed and all 28 action references are pinned, while eight workflows use read-only permissions. The audit reported a high-severity cache-poisoning pattern with low confidence; because it is low confidence and no untrusted checkout or script injection was found, this is a hygiene concern rather than a severe risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-23064
jquery is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.3 - 3.5.0 and 1.0.3 - 3.5.0.
1.0.3 - 3.5.0
Medium
CVE-2011-4969
jquery is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.6.3 and 0.0.0 - 1.6.3.
0.0.0 - 1.6.3
Medium
CVE-2012-6708
jquery is vulnerable to Windows Shortcut Following (.LNK) in versions 0.0.0 - 1.8.3 and 0.0.0 - 1.8.3.
0.0.0 - 1.8.3
Medium
CVE-2020-11023
jquery is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.3 - 3.5.0 and 1.0.3 - 3.5.0.
1.0.3 - 3.5.0
Medium
CVE-2019-5428
jquery is vulnerable to Security Vulnerability in versions 0.0.0 - 3.4.0 and 0.0.0 - 3.4.0.
0.0.0 - 3.4.0
Low

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 months ago
Created
15 years ago
Unpacked Size
2.8 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform