Package Health

liquidjs

A simple, expressive, extensible Liquid template engine for JavaScript — Shopify, Jekyll and GitHub Pages compatible, for Node.js, browsers, and the CLI, with TypeScript support.

Latest 10.30.0NPMNPM

88%

Total Score

healthy

Healthy: frequent releases and active contributors outweigh the workflow's unpinned action references.

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The project uses TypeScript, Rollup, and npm scripts, but no security scanning tools were detected; that is a modest transparency gap rather than a release-blocking concern.

Workflow auditcaution

All 10 workflows were analyzed with no audit findings or untrusted checkouts, and none grants top-level write access. However, all 31 action references are unpinned, leaving a reproducibility and workflow supply-chain hygiene gap.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-106120 New
liquidjs is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 10.27.1.
0.0.0 - 10.27.1
Medium
AIKIDO-2026-89061
liquidjs is vulnerable to Uncontrolled Resource Consumption in versions 10.15.0 - 10.27.1.
10.15.0 - 10.27.1
High
AIKIDO-2026-574329
liquidjs is vulnerable to Denial of Service (DoS) in versions 10.26.0 - 10.27.0.
10.26.0 - 10.27.0
High
AIKIDO-2026-500277 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
liquidjs is vulnerable to Information Disclosure in versions 9.34.0 - 10.27.1.
9.34.0 - 10.27.1
Low
AIKIDO-2026-127306
liquidjs is vulnerable to Allocation of Resources Without Limits or Throttling in versions 10.11.0 - 10.27.0.
10.11.0 - 10.27.0
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
commander
Version ^10.0.0
—
—

Weekly Downloads

Info

Last Published
9 days ago
Created
9 years ago
Unpacked Size
1.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform