XMLHttpRequest for Node
54%
Total Score
50
81
The latest release was published in October 2015, with no releases in the last 12 months; this is strong evidence of a stagnant dependency, though the repository was pushed more recently.
One registry maintainer creates a thin publishing base and a higher continuity risk for future releases, although registry access alone does not establish actual project activity.
The repository recorded zero commits and zero active maintainers in the last three months, indicating no current development capacity.
There are 69 open issues and 37 open pull requests, with no new or closed issues or merged pull requests in the last month, suggesting unresolved maintenance demand.
No type declarations are published, which reduces integration ergonomics for TypeScript consumers; this is a consumer convenience gap rather than an abandonment signal.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-28502 xmlhttprequest is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.7.0. | 0.0.0 - 1.7.0 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.