Is vite healthy, maintained, and safe?
Maintained, but watch it — vite has real signals (drift, thin maintenance, or advisories) worth tracking.
The verdict
vite earns a health score of 50/100, a medium risk rating, computed deterministically from live npm release history, maintainer data, and the OSV vulnerability database. Maintained, but watch it — vite has real signals (drift, thin maintenance, or advisories) worth tracking.
Its most recent release shipped on 22 July 2026 — 7 days ago — so development is clearly active. Across 746 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. Two maintainers are listed; better than a lone author, but still a thin bench if one steps away.
OSV lists 22 known advisories for vite, including 7 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
vite is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own package.json through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (22)
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
Vite's server.fs.deny bypassed with /. for files under project root
Vite's `server.fs.deny` did not deny requests for patterns with directories.
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
vite allows server.fs.deny bypass via backslash on Windows
Vite's `server.fs.deny` is bypassed when using `?import&raw`
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
launch-editor vulnerable to command injection via the crafted request on Windows
vite: `server.fs.deny` bypass on Windows alternate paths
Vite middleware may serve files starting with the same name with the public directory
Vite's `server.fs` settings were not applied to HTML files
Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Vite: `server.fs.deny` bypassed with queries
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Websites were able to send any requests to the development server and read the response in vite
Vite bypasses server.fs.deny when using ?raw??
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Key facts
- Latest version
- v8.1.5
- Last release
- 22 July 2026 (7 days ago)
- Total releases
- 746
- First release
- 21 April 2020
- Package age
- 6.3 years
- Maintainers
- 2
- Known advisories
- 22
- Confidence
- High
Frequently asked
Is vite still maintained?
Yes — vite released as recently as 22 July 2026 (7 days ago), so it is actively maintained.
Does vite have known security vulnerabilities?
Yes — OSV lists 22 advisories for vite. See the advisory list on this page for the OSV/GHSA identifiers.
Is vite safe to use?
Maintained, but watch it — vite has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 50/100 (medium risk) based on release recency, cadence, maintainer bus factor and known vulnerabilities.
Other npm packages we've checked
vite is one package. What about the other hundreds in your tree?
Paste your own package.json into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the npm registry & OSV.dev · snapshot generated 2026-07-28 · scores are deterministic and recomputed on each refresh.
