Dependency health Workspace

@qwik.dev/routernpm

Vulnerabilities, end of life and next steps

Check a specific version for known advisories, documented mitigations and evidence-backed earlier-version options. Maintenance health is separate from vulnerability status.

Review remediation options →
What the project says about itself
  • Build provenance — the latest release, 2.0.0-beta.43, carries a signed provenance attestation. Source: the registry.
  • Supported runtimenode ^18.17.0 || ^20.3.0 || >=21.0.0. Source: the registry.
  • Publishers on the registry — 8. Source: the registry.
  • Security policypublished. Source: the repository.
  • Open milestonesBACKLOG: Post v1.0 103/103 done; Priority 101/102 done; Planned 12/12 done; Transactional DOM updates 2/2 done; migrate to WebContainers 2/2 done. Source: the repository's milestones.

Third-party facts checked today; registry facts on every crawl.

State history 1
WhenChange
2026-09-14 first verdict: active

Badge

maintenance: active

Drop this in your README. It re-renders itself as the verdict changes.

[![maintenance](https://isitdeadyet.dev/badge/npm/@qwik.dev/router.svg)](https://isitdeadyet.dev/npm/@qwik.dev/router)

Watch it

Get told when @qwik.dev/router changes state, changes licence, or is deprecated — instead of finding out during an incident.

Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.