anti xss-library
74%
Total Score
caution
Long-term maintenance is active, but nearly all recent commits come from one contributor and CI needs workflow-hygiene attention.
The registry namespace and repository are owned by the same individual account, so there is no organizational backing shown to offset the concentrated contributor activity.
Although two contributors were active, one contributor made 51 of 52 recent commits, leaving maintenance highly concentrated and increasing continuity risk.
No repository security policy was found. For a package focused on filtering XSS, the absence of a documented vulnerability-reporting process is a transparency gap.
The single workflow was fully analyzed, uses read-only permissions, and pins all seven action references. However, it contains three high-confidence template-injection findings; template injection alone is a workflow-hygiene concern rather than evidence of an untrusted checkout or dangerous trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/portable-utf8 Version ~6.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.