npm package report

Is acorn safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/acorn
npm packagelast checked 2026-09-19

acorn · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 20 graph-tracked dependencies · provenance: none found

Re-check live →

SIGNALS
Advisory HistoryclearOK

7 historical advisory record(s) on this package (max severity HIGH). Add a version to check whether it is affected.

DEPENDENCIES
babel-core@^5.6.15clean
babelify@^5.0.4clean
browserify@^10.2.4clean
browserify-derequire@^0.9.4clean
eslint@^3.18.0clean
eslint-config-standard@^10.2.1clean
eslint-plugin-import@^2.2.0clean
eslint-plugin-node@^5.2.1clean
eslint-plugin-promise@^3.5.0clean
eslint-plugin-standard@^2.1.1clean
regenerate@~0.6.2clean
rollup@^0.34.1clean
rollup-plugin-buble@^0.11.0clean
test262@git+https://github.com/tc39/test262.git#18c1e799a01cc976695983b61e225ce7959bdd91clean
test262-parser-runner@^0.2.0clean
unicode-10.0.0@^0.7.5clean
unicode-11.0.0@^0.7.7clean
unicode-7.0.0@~0.1.5clean
unicode-8.0.0@^0.1.5clean
unicode-9.0.0@^0.7.0clean
PACKAGE acornECOSYSTEM npmDECISION ALLOW

Package facts

Weekly downloads
986M
GitHub stars
11.3k
Centrality tier
tier 1
Build provenance
none found
Direct dependencies
20

Baked snapshot · run a live check for the current verdict · browse all packages

Other package reports

acorn-class-fieldsacorn-dynamic-importacorn-globalsacemir__cssomacceptsabstract-leveldown

See all package reports or check any package live.