Package Health

terser

JavaScript parser, mangler/compressor and beautifier toolkit for ES6+

Latest 5.51.2NPMNPM

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

The package uses a prepare install-time lifecycle script. This is not inherently unsafe, but it increases installation complexity compared with a package having no lifecycle scripts.

Repo bus factorcaution

One contributor made 100% of the 26 recent commits. The organization-owned repository provides some handoff capacity, but the observed maintenance activity is still highly concentrated.

Repo commit activitycaution

There were 26 commits in the last 3 months, showing ongoing development. However, all were made by one active maintainer, which limits resilience.

Repo toolingcaution

The repository uses build tooling, but no security-scanning tools were detected. This is a transparency and assurance gap, though it is partly offset by the repository's other maintenance evidence.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-25858
terser is vulnerable to Inefficient Regular Expression Complexity in versions 0.0.0 - 4.8.1 and 5.0.0 - 5.14.2.
0.0.0 - 4.8.15.0.0 - 5.14.2
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
acorn
Version ^8.15.0
—
—
commander
Version ^2.20.0
—
—
source-map-support
Version ~0.5.20
—
—
@jridgewell/source-map
Version ^0.3.3
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
8 years ago
Unpacked Size
2.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform