`rrdom` is a virtual dom library that is used by `rrweb` to replay DOM mutations. It is a standalone library that can be used to create a virtual dom tree and apply patches to the real dom. It's used in `rrweb` to optimize replay performance especially wh
78%
Total Score
healthy
Healthy release with active maintenance and provenance, despite workflow secret exposure and an unclear package-to-repository link.
A prepublish lifecycle script is present. This is a mild supply-chain and reproducibility concern, although the package also has build provenance and an active source project.
The repository name does not match rrdom and its README does not mention the package. While a monorepo can explain the name mismatch, the absence of a package mention leaves the linkage less transparent.
All seven workflows were analyzed and scope permissions at job level, with no untrusted checkout or script-injection findings. However, 18 of 25 action references are unpinned and a high-confidence overprovisioned-secrets finding exposes the entire secrets context; the trusted-publishing finding also warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rrweb-snapshot Version ^2.1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.