npm package report

Is axios safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/axios
npm packagelast checked 2026-07-17

axios · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 15 graph-tracked dependencies · provenance: verified (sigstore)

Related research: full incident analysis · case study

Re-check live →

SIGNALS
Historical Compromise (resolved)resolvedOK

Version(s) 1.14.1, 0.30.4 were confirmed malicious and removed from the registry. The current version (1.18.1) is not affected.

Advisory HistoryclearOK

48 historical advisory record(s) on this package (max severity CRITICAL). Add a version to check whether it is affected.

Commit-Level AnalysisclearOK

15 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

Anomaly HistoryclearOK

1 historical anomaly alert(s) (version_jump) on this package. Add a version to check whether it is affected.

DEPENDENCIES
abortcontroller-polyfill@^1.5.0clean
auto-changelog@^2.4.0clean
@babel/core@^7.18.2clean
@babel/preset-env@^7.18.2clean
body-parser@^1.20.0clean
bundlesize@^0.17.0clean
chalk@^5.2.0clean
@commitlint/cli@^17.3.0clean
@commitlint/config-conventional@^17.3.0clean
coveralls@^2.11.2clean
cross-env@^7.0.3clean
dev-null@^0.1.1clean
dtslint@^4.1.6clean
es6-promise@^1.0.0clean
eslint@^8.17.0clean
PACKAGE axiosECOSYSTEM npmDECISION ALLOW

Baked snapshot · run a live check for the current verdict · browse all packages