Webpack plugin for enabling Subresource Integrity
57%
Total Score
67
100
83
50
The package has a prepublish lifecycle script. This is a limited supply-chain and install-behavior concern, though it is less severe than scripts that execute directly during installation.
The package has 50 releases over more than 10 years, but none in the last three months and its latest registry release was over three years ago. This indicates materially slowed release maintenance.
The repository recorded zero commits and zero active maintainers over the last three months. That is direct evidence of a thin or paused maintenance cadence.
There were no new or closed issues and no new or merged pull requests in the last month, while 18 issues and 16 pull requests remain open. This supports the concern that active maintenance is currently limited.
The repository uses webpack, TypeScript, and npm scripts, showing a defined build process, but no security-scanning tools were detected. The missing scanning is a modest hygiene gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-15262 webpack-subresource-integrity is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.0 - 1.5.1. | 0.0.0 - 1.5.1 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.