Package Health

maplibre-gl

BSD licensed community fork of mapbox-gl, a WebGL interactive maps library

Latest 6.14.0NPMNPM

91%

Total Score

healthy

A high-confidence release with 60 releases in 12 months and active repository work, tempered by one high-confidence workflow audit finding.

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The release declares BSD-3-Clause and includes a license file, so it is licensed; the artifact also detects MIT text, which is a minor declaration mismatch.

Lifecycle scriptscaution

The package has a prepare install-time lifecycle script, which adds some execution risk during installation, although no other evidence indicates suspicious behavior.

Workflow auditcaution

All five workflows were analyzed with no untrusted checkouts or script injection, and only 2 of 30 actions are unpinned; however, a high-confidence bot-conditions finding affects auto-merge logic, while broad write permissions remain a mild hygiene concern.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-516712
maplibre-gl is vulnerable to Cross-Site Scripting (XSS) in versions 5.0.0 - 6.4.0.
5.0.0 - 6.4.0
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
pbf
Version ^5.1.2
—
—
earcut
Version ^3.2.4
—
—
kdbush
Version ^4.1.0
—
—
bidi-js
Version ^1.1.0
—
—
potpack
Version ^2.1.0
—
—

Weekly Downloads

Info

Last Published
6 hours ago
Created
5 years ago
Unpacked Size
26.8 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform