{"package":"angular","ecosystem":"npm","latest_version":"1.8.3","description":"HTML enhanced for web apps","license":"MIT","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"http://angularjs.org","repository":"https://github.com/angular/angular.js","downloads_weekly":423645,"health":{"score":4,"risk":"critical","breakdown":{"maintenance":0,"popularity":14,"security":5,"maturity":15,"community":0},"deprecated":true,"max_score":100},"vulnerabilities":{"count":10,"critical":0,"high":2,"medium":5,"low":3,"details":[{"vuln_id":"CVE-2023-26117","severity":"medium","summary":"angular vulnerable to regular expression denial of service via the $resource service","affected_versions":"<=1.8.3","fixed_version":null,"source":"osv","published_at":"2023-03-30T06:30:26Z","in_kev":false,"epss_prob":0.01695,"epss_percentile":0.76109,"threat_tier":"theoretical"},{"vuln_id":"CVE-2023-26116","severity":"medium","summary":"angular vulnerable to regular expression denial of service via the angular.copy() utility","affected_versions":"<=1.8.3","fixed_version":null,"source":"osv","published_at":"2023-03-30T06:30:26Z","in_kev":false,"epss_prob":0.01695,"epss_percentile":0.76109,"threat_tier":"theoretical"},{"vuln_id":"CVE-2024-21490","severity":"high","summary":"angular vulnerable to super-linear runtime due to backtracking","affected_versions":">=1.3.0,<=1.8.3|>=1.3.0,<=1.8.3|>=1.3.0,<=1.8.3|=1.3.15|=1.3.16|=1.3.17|=1.3.20|=1.3.8|=1.4.0|=1.4.1|=1.4.14|=1.4.3|=1.4.4|=1.4.5|=1.4.6|=1.4.7|=1.4.8|=1.4.9|=1.5.0|=1.5.0-beta.0|=1.5.0-beta.2|=1.5.0-rc.0|=1.5.0-rc.1|=1.5.0-rc.2|=1.5.1|=1.5.10|=1.5.11|=1.5.2|=1.5.3|=1.5.5|=1.5.6|=1.5.7|=1.5.8|=1.5.9|=1.6.0|=1.6.0-rc.2|=1.6.1|=1.6.10|=1.6.2|=1.6.3|=1.6.4|=1.6.5|=1.6.6|=1.6.7|=1.6.8|=1.6.9|=1.7.0|=1.7.0-rc.0|=1.7.1|=1.7.2|=1.7.3|=1.7.4|=1.7.5|=1.7.6|=1.7.7|=1.7.8|=1.7.9|=1.8.0|=1.8.1|=1.8.2|=1.8.3|=1.3.0|=1.3.10|=1.3.11|=1.3.13|=1.3.14|=1.3.15|=1.3.16|=1.3.17|=1.3.18|=1.3.19|=1.3.2|=1.3.20|=1.3.6|=1.3.8|=1.4.0|=1.4.0-beta.5|=1.4.0-beta.6|=1.4.0-rc.1|=1.4.0-rc.2|=1.4.1|=1.4.11|=1.4.12|=1.4.14|=1.4.2|=1.4.3|=1.4.4|=1.4.5|=1.4.6|=1.4.7|=1.4.8|=1.4.9|=1.5.0|=1.5.0-beta.0|=1.5.0-beta.2|=1.5.0-rc.0|=1.5.0-rc.1|=1.5.0-rc.2|=1.5.1|=1.5.10|=1.5.11|=1.5.2|=1.5.3|=1.5.4|=1.5.5|=1.5.6|=1.5.7|=1.5.8|=1.5.9|=1.6.0|=1.6.0-rc.2|=1.6.1|=1.6.10|=1.6.2|=1.6.3|=1.6.4|=1.6.5|=1.6.6|=1.6.7|=1.6.7-1|=1.6.8|=1.6.9|=1.7.0|=1.7.0-rc.0|=1.7.1|=1.7.2|=1.7.3|=1.7.4|=1.7.5|=1.7.6|=1.7.7|=1.7.8|=1.7.9|=1.8.0|=1.8.2|=1.8.3","fixed_version":null,"source":"osv","published_at":"2024-02-10T06:30:19Z","in_kev":false,"epss_prob":0.01891,"epss_percentile":0.78638,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-11998","severity":"high","summary":"Angular's deprecated package has a Cross-Site Scripting issue","affected_versions":">=1.2.0-rc.3,<=1.8.3","fixed_version":null,"source":"osv","published_at":"2026-06-24T21:30:44Z","in_kev":false,"epss_prob":0.00502,"epss_percentile":0.41951,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-0716","severity":"low","summary":"AngularJS improperly sanitizes SVG elements","affected_versions":"<=1.8.3","fixed_version":null,"source":"osv","published_at":"2025-04-29T18:30:59Z","in_kev":false,"epss_prob":0.00399,"epss_percentile":0.34004,"threat_tier":"theoretical"},{"vuln_id":"CVE-2022-25844","severity":"medium","summary":"angular vulnerable to regular expression denial of service (ReDoS)","affected_versions":">=1.7.0","fixed_version":null,"source":"osv","published_at":"2022-05-03T00:00:44Z","in_kev":false,"epss_prob":0.04927,"epss_percentile":0.91727,"threat_tier":"theoretical"},{"vuln_id":"CVE-2024-8372","severity":"low","summary":"AngularJS allows attackers to bypass common image source restrictions","affected_versions":">=1.3.0-rc.4,<=1.8.3","fixed_version":null,"source":"osv","published_at":"2024-09-09T15:30:41Z","in_kev":false,"epss_prob":0.00609,"epss_percentile":0.47783,"threat_tier":"theoretical"},{"vuln_id":"CVE-2024-8373","severity":"low","summary":"AngularJS allows attackers to bypass common image source restrictions","affected_versions":"<=1.8.3","fixed_version":null,"source":"osv","published_at":"2024-09-09T15:30:41Z","in_kev":false,"epss_prob":0.00635,"epss_percentile":0.49028,"threat_tier":"theoretical"},{"vuln_id":"CVE-2022-25869","severity":"medium","summary":"Angular (deprecated package) Cross-site Scripting","affected_versions":"<=1.8.3","fixed_version":null,"source":"osv","published_at":"2022-07-16T00:00:20Z","in_kev":false,"epss_prob":0.07266,"epss_percentile":0.9406,"threat_tier":"theoretical"},{"vuln_id":"CVE-2023-26118","severity":"medium","summary":"angular vulnerable to regular expression denial of service via the <input type=\"url\"> element","affected_versions":"<=1.8.3","fixed_version":null,"source":"osv","published_at":"2023-03-30T06:30:25Z","in_kev":false,"epss_prob":0.01695,"epss_percentile":0.7611,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"1.8.3","total_count":144,"recent":["1.6.6","1.6.7","1.6.8","1.6.9","1.6.10","1.7.0-rc.0","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9","1.8.0","1.8.1","1.8.2","1.8.3"]},"metadata":{"deprecated":true,"deprecated_message":"For the actively supported Angular, see https://www.npmjs.com/package/@angular/core. AngularJS support has officially ended. For extended AngularJS support options, see https://goo.gle/angularjs-path-forward.","maintainers_count":1,"first_published":"2012-03-28T11:40:21.575Z","last_published":"2022-04-07T22:12:36.643Z","dependencies_count":0,"dependencies":[]},"github_stats":{"stars":58747,"forks":27173,"open_issues":461,"is_archived":true,"pushed_at":"2024-04-12T17:43:16+00:00"},"bundle":{"size_kb":178.9,"gzip_kb":62.2,"dependency_count":0,"has_js_module":false,"has_side_effects":true,"scoped":false,"source":"bundlephobia"},"typescript":{"score":7,"has_types":true,"types_source":"definitely-typed","types_package":"@types/angular"},"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"find_alternative","issues":["Moderate health score (4/100) — verify manually","2 high severity vulnerabilities","Package is deprecated"],"use_version":"1.8.3","version_hint":null,"summary":"angular is deprecated — find an alternative","alternatives":[{"name":"@angular/core","reason":"AngularJS (1.x) is EOL; use modern Angular","builtin":false}]},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/npm/angular","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/npm/angular","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/npm/angular","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate","hint_bulk":"You've called /api/check 68 times in 60s. Save bandwidth + tokens with POST /api/check_bulk (1 round-trip for N pkgs)."},"requested_version":null,"_cache":"hit","_response_ms":0,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":true,"criticality_score":0.627,"criticality_tier":"high","velocity_pct":null,"velocity_trend":null,"publish_security":null},"alternatives_link":{"url":"/api/alternatives/npm/angular","count":1},"version_history_summary":{"total_versions":20,"first_release_age_days":5290,"last_release_days_ago":1627,"avg_days_between_releases":278,"release_velocity":"stale"}}