depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access

Related on DepScope

Alternatives
  • sass— A pure JavaScript implementation of Sass.
  • jpeg-js— A pure javascript JPEG encoder and decoder
  • bmp-js— A pure javascript BMP encoder and decoder
More
  • All npm packages →
  • Breaking changes index →
  • Bug index →
  • AI hallucination corpus →
depscope/npm/xmldom

xmldom

npmv0.6.0

A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.

License MITpermissive36 versions2 maintainers0 deps1,624,026 weekly dl
xmldom/xmldom
40
/ 100
Health
do not use

xmldom has critical vulnerabilities — do not use

Update to >= 0.9.10 to fix known vulnerabilities

  • Moderate health score (40/100) — verify manually
  • 5 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
25/25
maintenance
17/20
popularity
0/25
security
15/15
maturity
5/15
community
0/15
popularity_floor
Vulnerabilities
7
1 critical5 high1 medium
Advisories (7)
SeverityIDSummaryFixed in
highCVE-2026-41673xmldom: Uncontrolled recursion in XML serialization leads to DoS0.9.10
mediumCVE-2021-32796Misinterpretation of malicious XML input0.7.0
criticalCVE-2022-39353xmldom allows multiple root nodes in a DOM0.9.0-beta.4
highCVE-2026-41674xmldom has XML injection through unvalidated DocumentType serialization0.9.10
highCVE-2026-41672xmldom has XML node injection through unvalidated comment serialization0.9.10
highCVE-2026-34601xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion0.9.9
highCVE-2026-41675xmldom has XML node injection through unvalidated processing instruction serialization0.9.10

Bundle & TypeScript

📦

Bundle Size

28.0 KBminified
10.1 KB gzipped
0 direct dependencies
side effects
🌟

TypeScript

7/10typed
Types from @types/xmldom (DefinitelyTyped)
Quality signals
Publish security
npm signed

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/npm/xmldom
More from npm
?semverminimatchdebugbrace-expansionstrip-ansi
Browse all npm packages →

First published · 2012-01-06T09:49:36.833Z

Last updated · 2021-04-17T16:41:51.033Z

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents