npm package report

Is jsdom safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/jsdom
npm packagelast checked 2026-06-10

jsdom · verdict ALERT · review advised

2.4/10
XYZ SCORE
SUMMARY

Verdict ALERT · 40 known dependencies · provenance: verified (sigstore)

Re-check live →

SIGNALS
Commit-Level AnalysistriggeredHIGH

29.1.0

Anomaly HistoryclearOK

1 historical anomaly alert(s) (transitive_malicious_dep) on this package. Add a version to check whether it is affected.

DEPENDENCIES
abab@^1.0.0clean
abab@^1.0.3clean
abab@^1.0.4clean
abab@^2.0.0clean
abab@^2.0.3clean
abab@^2.0.5clean
abab@^2.0.6clean
acorn@0.11.0clean
acorn@>= 0.12.0 < 0.13.0clean
acorn@^1.0.3clean
acorn@^1.2.1clean
acorn@^2.4.0clean
acorn@^4.0.4clean
acorn@^5.1.2clean
acorn@^5.3.0clean
acorn@^5.5.3clean
acorn@^5.7.1clean
acorn@^6.0.2clean
acorn@^6.0.4clean
acorn@^6.1.1clean
PACKAGE jsdomECOSYSTEM npmDECISION ALERT

Baked snapshot · run a live check for the current verdict · browse all packages