PkgRadar

npm · registry.npmjs.org

axe-core

Remote Dependency Spec: devDependencies.aria-practices="github:w3c/aria-practices#ce0336bd82d7d3651abcbde86af644197ddbc629"

Why PkgRadar flagged 4.11.1

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.aria-practices="github:w3c/aria-practices#ce0336bd82d7d3651abcbde86af644197ddbc629" · package.json
mediumRemote Dependency SpecdevDependencies.wcag-act-rules="github:w3c/wcag-act-rules#5adb55d19eb2cd7fb23213b2d1acedf9004dc063" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.11.1Review42026-06-16
4.11.3Review42026-06-15
4.12.1-canary.f0a12cfReview42026-06-15
4.12.1-canary.24cef87Review42026-06-15
4.11.4Review42026-06-15
4.12.1-canary.27a4686Review42026-06-12
4.12.1-canary.00519ccReview42026-06-12
4.12.1-canary.a10bc44Review42026-06-12
4.12.1-canary.489cdeaReview42026-06-12
4.12.1-canary.4b6f0d5Review42026-06-10
4.12.1-canary.6c41927Review42026-06-10
4.12.1-canary.a8669e1Review42026-06-10
4.12.1-canary.61f2624Review42026-06-10
4.12.1Review42026-06-10
4.12.0-canary.81853d9Review42026-06-09
4.12.0-canary.90fce18Review42026-06-09
4.12.0-canary.88ee9a3Review42026-06-08
4.12.0-canary.a7d8f3eReview42026-06-08
4.12.0-canary.46a0eadReview42026-06-01
4.12.0Review42026-06-01
4.11.4-canary.7d9d696Review42026-05-27
4.11.4-canary.3a012a1Review42026-05-27
4.11.4-canary.c01a37dReview42026-05-27

Block this in CI

PkgRadar gates axe-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]