Find vulnerable JavaScript libraries on a live website
The libraries a site ships run in every visitor's browser. RepoVerse finds which ones, at which version, straight from the live site — including inside minified bundles — and checks each against known advisories.
Where versions come from
A version is an inference, so the report always says how it was read.
- CDN paths and file names: cdnjs, unpkg, jsDelivr, code.jquery.com, WordPress ?ver= style names
- Licence banners anywhere in a file, including esbuild's end-of-file comments and webpack's .LICENSE.txt
- Version strings that survive minification next to code only that library has
- Angular's ng-version stamp in the page HTML
- Published source maps, including pnpm install paths and original library files
Libraries it recognises
Inside minified bundles: jQuery, lodash, moment, Handlebars, DOMPurify, Vue 2, Bootstrap, axios (from 0.22), react-dom, Next.js and AngularJS. From banners, file names and the page: jQuery UI, underscore, Popper, Vue 3, Angular and more, plus any npm package loaded from unpkg or jsDelivr with its version in the URL. Each is checked against OSV, and the report gives the release that fixes all of its advisories.
Tested on real builds
Nine library versions with known advisories were bundled with Vite and with webpack exactly as a production build would, and the bundles were served as a site. Before this detection existed the review found one of them; it now finds eight in each build. The ninth, axios 0.21, carries no version string in its code, which no passive check can read without a source map.
What it checks
- HighFront-end library with known vulnerabilities
The page ships a library version that has published advisories; the vulnerable code runs in every visitor's browser.
website · CWE-1104
- LowThird-party script loaded without integrity check
If the CDN or the other site is compromised, the script it serves runs on your pages with full access — the supply-chain path behind several card-skimming attacks.
website · CWE-353
- LowSource maps are public
Anyone can download the original, unminified source — comments, internal API routes, feature flags and code paths you did not mean to publish — which makes the next attack easier to plan.
website · CWE-540
Questions
- Is this a retire.js alternative?
- It answers the same question — which known-vulnerable JavaScript a site ships — from the live site without installing anything, and adds the other checks of a website security review in the same report.
- How do I fix a vulnerable library the scan finds?
- Upgrade to the fixed release the report names and redeploy. If the library comes from a CDN, change the version in the script URL and add a Subresource Integrity hash. If nothing uses it any more, remove it.
- Why does it say a version was inferred?
- Because it was read from a file name, a banner or a code pattern rather than from the package itself. These are reliable in practice, and labelling them keeps the difference between a fact and a strong inference visible.
Related
- Website security scanner that shows its evidenceFree passive website security scan: HTTPS and HSTS, CSP, cookies, mixed content, exposed keys and outdated JavaScript libraries — with the exact header behind each finding.
- Vulnerable dependencies: the code you did not writeMost application code is third-party. How vulnerable dependencies get into a project (CWE-1395), why the lockfile is what matters, and how to pick the upgrade that fixes it.
- Cross-site scripting (XSS): how it works and how to stop itReflected, stored and DOM-based XSS (CWE-79) explained with vulnerable and fixed code, plus the template, CSP and cookie settings that limit the damage.
Updated 2026-10-11