Package Health

react-dev-utils

webpack utilities used by Create React App

Latest 12.0.1NPMNPM

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

Twenty-four runtime dependencies create a broad dependency surface for a utility package, increasing maintenance exposure, though the signal does not show a specific problematic dependency.

Release historycaution

The package has 116 releases over about 10 years, but it has had no release in the last 12 months and the latest release was about 19 months ago, indicating stalled maintenance.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, showing that current development activity has effectively stopped.

Repo issue activitycaution

The repository still has substantial issue and pull-request volume, but only one pull request was merged in the last month while three were opened, suggesting limited current follow-through.

Repo package mentioncaution

The repository name does not match react-dev-utils and its README does not mention the package, which creates some uncertainty about package-to-repository alignment; the organization-owned monorepo context partly compensates.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-14802
react-dev-utils is vulnerable to Improper Neutralization of Special Elements used in a Command ('Command Injection') in versions 0.0.0 - 5.0.1.
0.0.0 - 5.0.1
High
CVE-2021-24033
react-dev-utils is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.4.0 - 11.0.4.
0.4.0 - 11.0.4
Medium
CVE-2018-6342
react-dev-utils is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 1.0.0 - 1.0.4, 2.0.0 - 2.0.2, 3.0.0 - 3.1.2, 4.0.0 - 4.2.2 and 5.0.0 - 5.0.2.
1.0.0 - 1.0.42.0.0 - 2.0.23.0.0 - 3.1.2 +2 more
Critical

Package versions

Direct Dependencies

DependencyLast ReleaseScore
open
Version ^8.4.0
—
—
chalk
Version ^4.1.2
—
—
immer
Version ^9.0.7
—
—
globby
Version ^11.0.4
—
—
pkg-up
Version ^3.1.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
10 years ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform