mupdf 1.28.1 appears to be a mature, stable release with a clear AGPL-3.0-or-later license, bundled TypeScript declarations, no runtime dependencies, and a sustained release history since January 2023. It is not deprecated and uses a stable major version, while the prepack script is consistent with producing a WebAssembly distribution. However, no source repository is declared, so repository maintenance, contributor activity, issue handling, and build transparency cannot be verified; the artifact also lacks packaged tests and a changelog, and has no build provenance attestation. The package is usable, but adopting it carries moderate transparency and verification risk.
70%
Total Score
50
100
92
100
50
No build attestation, trusted publisher identity, staged publishing, or approver is recorded. For a compiled WebAssembly artifact this limits verifiability of how the published binaries were produced.
Only one registry account, artifex-js, has publish access. This does not establish actual maintenance activity, but it does indicate a narrow publication control base and limited redundancy if that account becomes inactive.
The artifact includes a substantive README, but no packaged tests or changelog are present. Because this is a compact WebAssembly distribution, the missing tests and changelog are a hygiene gap, though not evidence of abandonment by themselves.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-663140 mupdf is vulnerable to Integer Overflow in versions 1.26.2 - 1.27.0. | 1.26.2 - 1.27.0 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.