npm package report

Is happy-dom safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/happy-dom
npm packagelast checked 2026-09-19

happy-dom · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 18 graph-tracked dependencies · provenance: verified (sigstore)

Re-check live →

SIGNALS
Advisory HistoryclearOK

5 historical advisory record(s) on this package (max severity CRITICAL). Add a version to check whether it is affected.

Commit-Level AnalysisclearOK

4 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

DEPENDENCIES
css.escape@^1.5.1clean
css-tree@^1.0.0-alpha.29clean
entities@^4.5.0clean
eslint@^5.16.0clean
eslint-config-prettier@^4.1.0clean
eslint-plugin-filenames@^1.3.2clean
eslint-plugin-import@^2.22.1clean
eslint-plugin-jest@^24.1.0clean
eslint-plugin-jsdoc@^30.4.0clean
eslint-plugin-json@^2.0.1clean
eslint-plugin-prettier@^3.0.1clean
eslint-plugin-turbo@^0.0.7clean
he@^1.1.1clean
iconv-lite@^0.6.3clean
jest@^24.9.0clean
memory-fs@^0.5.0clean
node-fetch@2.5.0clean
prettier@^1.16.4clean
PACKAGE happy-domECOSYSTEM npmDECISION ALLOW

Package facts

Weekly downloads
11.3M
GitHub stars
4.2k
Centrality tier
tier 1
Build provenance
verified (sigstore)
Direct dependencies
18

Baked snapshot · run a live check for the current verdict · browse all packages

Other package reports

helmethighlight.jshtml-webpack-pluginhapihandlebarsgulp

See all package reports or check any package live.