preact-parser

MITLicense declared in the package manifest.

When dealing with HTML strings in Preact, our only real option is to use `dangerouslySetInnerHTML`. This is fine(-ish) if you 100% trust the contents of that HTML, but regardless, it opens up potential vectors for attack, problems and bugs. Ideally, we'd

85

Security score

0 known advisories in v1.3.7

0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.advisory penalty −0 · staleness penalty −15

Weekly downloads

Downloads across all versions in the last 7 days, from the official npm downloads API (api.npmjs.org).

Unpacked size

Size of v1.3.7 on disk after npm install extracts the tarball, as reported by the npm registry.

11.6 kB

Dependencies

Direct runtime dependencies declared by v1.3.7. Transitive dependencies are not counted here — use the lockfile audit for the full tree.

0

Last publish

When v1.3.7 was published to the registry. Long gaps can indicate an unmaintained package.

3 years ago

Security advisories

Vulnerabilities affecting v1.3.7 specifically, from OSV.dev — the open database aggregating the GitHub Advisory Database (GHSA) and CVEs. Links open the full advisory.

No known vulnerabilities affect v1.3.7.