# retire.js

> Scanning website for vulnerable js libraries.

Canonical page: [https://chrome-stats.com/d/retire-js](https://chrome-stats.com/d/retire-js)

## Overview

- **ID:** `retire-js`
- **Platform:** Firefox
- **Type:** Firefox add-on
- **Status:** Available
- **Publisher:** Francesco De Stefano
- **Category:** web-development,privacy-security
- **Daily users:** 4,898
- **Weekly downloads:** 202
- **Rating:** 4.73 / 5 (11 ratings)
- **Version:** 2.3.2
- **Last updated:** 2026-05-31
- **First published:** 2017-04-22
- **Size:** 178 KB
- **Data as of:** 2026-09-14
- **Store listing:** [Firefox Add-ons Store](https://addons.mozilla.org/firefox/addon/retire-js/)

## Description

**Retire.js** is a powerful Chrome extension designed to scan web applications for vulnerable JavaScript libraries. It helps developers and security professionals identify outdated or insecure versions of popular JS libraries, protecting websites from potential exploits related to known vulnerabilities.

This extension updates its vulnerability repository regularly, incorporating information from sources such as OSV. Key features include detection of vulnerabilities in libraries like jQuery UI, Next.js, Angular, and more. Retire.js also offers options to display unknown libraries, enhancing a comprehensive security audit.

Note that Retire.js is based on the original Retire.js project and is intended to be used responsibly, respecting all local and federal laws. It is an essential tool for anyone looking to improve the security posture of their web applications by proactively scanning for outdated JavaScript dependencies.

## Rankings

- #1,220 — Overall
- #129 — Web Development
- #252 — Privacy & Security
- #15 — jquery
- #19 — disclaimer
- #24 — return

## Permissions and access

### Permissions

- `<all_urls>`
- `webRequest`
- `tabs`

### Content script matches

- `<all_urls>`

## Safety

- **Risk impact:** High risk impact
- **Risk likelihood:** Moderate risk likelihood

### Analysis details

- Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
- This extension has low user count. Unpopular extensions may not be stable or safe.

> Some risk analysis details are omitted from this free response. [Upgrade to view the full analysis](https://chrome-stats.com/pricing).

## Review summary

### Pros

- Useful for developers
- Effective at identifying out-of-date JavaScript libraries
- Easy to understand at a glance

### Cons

- Missing dark mode
- Need for improved table layout
- No sorting options for results

## Similar extensions and apps

- [Retire.JS Pro](https://chrome-stats.com/d/retire-js-pro) — 26 users
- [JS Recon Buddy](https://chrome-stats.com/d/js-recon-buddy) — 171 users, 5.00 / 5
- [Dependency Security Scanner](https://chrome-stats.com/d/dependency-security-scanner) — 1 users
- [Defendshield VulnTrace](https://chrome-stats.com/d/defendshield-vulntrace) — 2 users
- [Vulnerability Scanner](https://chrome-stats.com/d/vulnerability-scanner) — 10 users
- [LibJS Detector](https://chrome-stats.com/d/libjs-detector) — 77 users, 5.00 / 5
- [Library Detector Pro](https://chrome-stats.com/d/library-detector-pro) — 7 users
- [Jsmon](https://chrome-stats.com/d/jsmon) — 5 users
- [JS Analyzer](https://chrome-stats.com/d/js-analyzer) — 46 users
- [React2shell - RSC Sentinel](https://chrome-stats.com/d/react2shell-rsc-sentinel) — 125 users, 5.00 / 5
- [Secret Scanner](https://chrome-stats.com/d/secret-scanner) — 2 users
- [JS Lib Detector](https://chrome-stats.com/d/js-lib-detector) — 2 users

---

Source: [Chrome-Stats](https://chrome-stats.com/d/retire-js)
