BSD licensed community fork of mapbox-gl, a WebGL interactive maps library
91%
Total Score
healthy
A high-confidence release with 60 releases in 12 months and active repository work, tempered by one high-confidence workflow audit finding.
The release declares BSD-3-Clause and includes a license file, so it is licensed; the artifact also detects MIT text, which is a minor declaration mismatch.
The package has a prepare install-time lifecycle script, which adds some execution risk during installation, although no other evidence indicates suspicious behavior.
All five workflows were analyzed with no untrusted checkouts or script injection, and only 2 of 30 actions are unpinned; however, a high-confidence bot-conditions finding affects auto-merge logic, while broad write permissions remain a mild hygiene concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-516712 maplibre-gl is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 6.4.0. | 5.0.0 - 6.4.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
pbf Version ^5.1.2 | — | — |
earcut Version ^3.2.4 | — | — |
kdbush Version ^4.1.0 | — | — |
bidi-js Version ^1.1.0 | — | — |
potpack Version ^2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.