template compiler for Vue 2.0
61%
Total Score
67
100
85
67
The package has 147 releases over more than 10 years, but none in the last 12 months and its latest release was on December 24, 2023. The long history shows maturity, while the stopped release cadence raises abandonment risk for new adopters.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is the clearest maintenance concern, although the repository's recent push and the package's documented final-release status provide context.
In the last month, one issue was opened and no issues were closed; four pull requests were opened and none were merged. This indicates little evidence of ongoing issue or review throughput.
The repository name does not match this sub-package and its README does not mention vue-template-compiler. That weakens package-to-repository transparency, although a name mismatch can be normal for a monorepo sub-package.
The repository uses established build tools, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-6783 vue-template-compiler is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.0 - 3.0.0. | 2.0.0 - 3.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
he Version ^1.2.0 | — | — |
de-indent Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.