npm package report

Is core-js safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/core-js
npm packagelast checked 2026-09-19

core-js · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 6 graph-tracked dependencies · provenance: none found

Re-check live →

SIGNALS
Commit-Level AnalysisclearOK

6 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

DEPENDENCIES
browserify@9.0.xclean
eslint@0.18.xclean
eslint-plugin-import@2.10.xclean
es-observable-tests@0.2.xclean
grunt@*clean
grunt-cli@0.1.xclean
PACKAGE core-jsECOSYSTEM npmDECISION ALLOW

Package facts

Weekly downloads
130M
GitHub stars
25.4k
Centrality tier
tier 1
Build provenance
none found
Direct dependencies
6

Baked snapshot · run a live check for the current verdict · browse all packages

Other package reports

corscosmiconfigcross-envcopy-webpack-plugincookiecontent-type

See all package reports or check any package live.