Package Health

next

The React Framework

Latest 16.2.4NPMNPM

95%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

95

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Vulnerabilities

TitleVersionsSeverity
CVE-2026-29057
next is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 16.0.0-beta.0 - 16.1.7 and 9.5.0 - 15.5.13.
9.5.0 - 15.5.1316.0.0-beta.0 - 16.1.7
Medium
CVE-2026-27980
next is vulnerable to Uncontrolled Resource Consumption in versions 16.0.0-beta.0 - 16.1.7 and 10.0.0 - 15.5.14.
10.0.0 - 15.5.1416.0.0-beta.0 - 16.1.7
Medium
CVE-2026-27979
next is vulnerable to Allocation of Resources Without Limits or Throttling in versions 16.0.1 - 16.1.7.
16.0.1 - 16.1.7
Medium
CVE-2026-27978
next is vulnerable to Cross-Site Request Forgery (CSRF) in versions 16.0.1 - 16.1.7.
16.0.1 - 16.1.7
Medium
CVE-2026-27977
next is vulnerable to Missing Origin Validation in WebSockets in versions 16.0.1 - 16.1.7.
16.0.1 - 16.1.7
Low

Package versions

Direct Dependencies

DependencyLast ReleaseScore
postcss
Version 8.4.31
@next/env
Version 16.2.4
styled-jsx
Version 5.1.6
@swc/helpers
Version 0.5.15
caniuse-lite
Version ^1.0.30001579

Weekly Downloads

Info

Last Published
3 days ago
Created
14 years ago
Unpacked Size
147.3 MB