Is underscore healthy, maintained, and safe?
No — underscore carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
The verdict
underscore earns a health score of 53/100, a medium risk rating, computed deterministically from live npm release history, maintainer data, and the OSV vulnerability database. No — underscore carries 1 unpatched critical advisory and should not be adopted without a remediation plan.
The last release was 19 February 2026 (158 days ago); still within a normal window, but the cadence has quietened. Across 55 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. Two maintainers are listed; better than a lone author, but still a thin bench if one steps away.
OSV lists 2 known advisories for underscore, including 1 critical and 1 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.
underscore is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own package.json through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (2)
Arbitrary Code Execution in underscore
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
Key facts
- Latest version
- v1.13.8
- Last release
- 19 February 2026 (158 days ago)
- Total releases
- 55
- First release
- 9 January 2011
- Package age
- 15.6 years
- Maintainers
- 2
- Known advisories
- 2
- Confidence
- High
Frequently asked
Is underscore still maintained?
Partly — the most recent release was 19 February 2026 (158 days ago), so maintenance has slowed but not fully stopped.
Does underscore have known security vulnerabilities?
Yes — OSV lists 2 advisories for underscore, including 1 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.
Is underscore safe to use?
No — underscore carries 1 unpatched critical advisory and should not be adopted without a remediation plan. OSPulse rates it 53/100 (medium risk) based on release recency, cadence, maintainer bus factor and known vulnerabilities.
Alternatives to underscore
Other npm packages we've checked
underscore is one package. What about the other hundreds in your tree?
Paste your own package.json into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the npm registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
