npm package report

Is ua-parser-js safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/ua-parser-js
npm packagelast checked 2026-07-17

ua-parser-js · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 17 graph-tracked dependencies · provenance: verified (sigstore)

Re-check live →

SIGNALS
Historical Compromise (resolved)resolvedOK

Version(s) 0.7.29, 0.8.0, 1.0.0 were confirmed malicious and removed from the registry. The current version (2.0.10) is not affected.

Advisory HistoryclearOK

9 historical advisory record(s) on this package (max severity CRITICAL). Add a version to check whether it is affected.

Commit-Level AnalysisclearOK

5 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

DEPENDENCIES
@babel/parser@7.15.8clean
@babel/traverse@7.15.4clean
detect-europe-js@^0.1.1clean
is-standalone-pwa@^0.1.0clean
@jazzer.js/core@^1.4.0clean
jshint@~1.1.0clean
mocha@~1.7.1clean
node-fetch@^2.7.0clean
@playwright/test@~1.32.2clean
requirejs@^2.3.2clean
safe-regex@^2.1.1clean
tsd@^0.29.0clean
@types/node@^22.9.1clean
@types/node-fetch@^2.6.12clean
ua-is-frozen@^0.1.1clean
uglify-js@~1.3.4clean
verup@^1.3.xclean
PACKAGE ua-parser-jsECOSYSTEM npmDECISION ALLOW

Baked snapshot · run a live check for the current verdict · browse all packages