clevertap-web-sdk

CleverTap Web SDK

JavaScript v2.5.5 ๐Ÿ”’ 2 vulns ยท HIGH ๐Ÿ“ฆ 89.6K/mo ๐Ÿ” 5.6/10
16 stars  ยท  19 forks  ยท  Updated  ยท  MIT
Install
npm install clevertap-web-sdk
View on GitHub
๐Ÿ“„ Documentation
analyticsclevertapclevertap-web-sdkengagementjavascriptnpm-packageuser-retentionweb-sdk
Supported APIs (1)
Version history All releases โ†—

- Added support for remote interaction for Web Popups, Native Display and Inbox on TV platforms.

- Added Clevertap Custom Id Support in On User Login.

## What's Changed * chore: migrate semaphore pipelines to ARM (Graviton) by @Yashprime1 in https://github.com/CleverTap/clevertap-web-sdk/pull/512 *โ€ฆ

## What's Changed * Support for srcset and sizes for image in visual editor by @ThisIsRaghavGupta in https://github.com/CleverTap/clevertap-web-sdk/pโ€ฆ

- Fixed the campaign delivery triggers logic

## What's Changed * Encryption in transit web sdk by @kkyusuftk in https://github.com/CleverTap/clevertap-web-sdk/pull/468 * Develop by @kkyusuftk iโ€ฆ

- Added Nested object support in profile and event properties.

## What's Changed * semaphore: replacing semaphore agents with newer upstreamed agents by @Yashprime1 in https://github.com/CleverTap/clevertap-web-sโ€ฆ

๐Ÿ”’ Security advisories (2)
HIGH
CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function
CVE: CVE-2026-26861Fixed in 1.15.3Details โ†—
HIGH
CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage
CVE: CVE-2026-26862Fixed in 1.15.3Details โ†—
Data from OSV.dev
Quality signals
Score
Stars16
Forks19
Last updated
LicenseMIT
Supported APIs (1)
clever.com
๐Ÿ“ฆ Package statsnpm โ†—
Monthly downloads89.6K
Bundle size (gzip)86.1 kB
Bundle (minified)286.3 kB
Used by packages2
5.6
OpenSSF Scorecard
out of 10 ยท 2026-03-02
Full report โ†—
๐Ÿ‘๏ธ Code Review
9/10
๐Ÿ”„ Maintained
10/10
๐Ÿช™ Token Permissions
0/10
๐Ÿ“‹ Security Policy
0/10
๐Ÿ” Branch ProtectionN/A
๐Ÿ” Static Analysis (SAST)
0/10