@cyberhub/trust-ua-parser-js
v1.0.7
Published
Security Trust Report: [email protected] — 65/100 (B, standard). 5 vulnerabilities found. Maintainer risk, supply chain analysis from 8 security databases.
Maintainers
Readme
Security Trust Report: ua-parser-js
[email protected]: 65/100 | Grade: B | Tier: STANDARD (confidence: ±3)
Scanned on 2026-04-03 from 8 security databases. View package on npm →
TL;DR
- 5 vulnerabilities found (0 critical, 5 high)
- Pin your version and monitor for changes
⚠️ Security Incident Background
In October 2021, versions 0.7.29, 0.8.0, and 1.0.0 were hijacked via a compromised npm account. Malicious code installed a cryptominer and password stealer on affected machines.
Score Breakdown
Maintainer Trust: █████████████████░░░ 87/100
Package Health: █████████████████░░░ 83/100
Supply Chain: ░░░░░░░░░░░░░░░░░░░░ 0/100
Community: ███████████████████░ 93/100Why this score?
- Supply Chain is 0 because: 5 known CVEs, in breach database
Vulnerabilities (5 vulnerabilities)
| Severity | Count | |----------|-------| | 🟠 High | 5 |
- CVE-2022-25927
- GHSA-fhg7-m89q-25r3
- CVE-2020-7793
- GHSA-394c-5j6w-4xmx
- CVE-2021-4229
- GHSA-pjwm-rvh2-c87w
- CVE-2020-7733
- GHSA-662x-fhqg-9p8v
Key Risk Flags
- 🔴 CRITICAL: HISTORICAL BREACH: Cryptominer injected in v0.7.29/0.8.0/1.0.0 (2021) (evidence)
- 🟠 HIGH: Package size doubled between versions
- 🟠 HIGH: 5 HIGH vulnerabilities detected
🛠️ What Should You Do?
Immediate:
- 📌 Pin to known-safe version: 0.7.28 or 1.0.33+ (patched)
- 📖 Review the security incident above
Always: Pin version, run pkgtrust scan in CI, monitor at nrupak.com/trust/ua-parser-js
Maintainers (1)
- faisalman ✅ 2FA (freemail) — Trust profile
Methodology: 18+ signals across 4 categories (Maintainer 35%, Package 25%, Supply Chain 25%, Community 15%). Full scoring docs →
Check your project: npm i -g @cyberhub/pkgtrust && pkgtrust scan ua-parser-js — CLI docs
Data Sources: GitHub Advisories · OSV.dev · npm audit · Snyk · Socket.dev · npms.io · Bundlephobia · deps.dev
Report by pkgtrust · Dashboard · Compare · CLI
This is an automated security report. Not affiliated with the ua-parser-js team. Updated 2026-04-03.
