shouldiuse.io

Report

Should I Use UNPKG?

unpkg.com·Analyzed 4 hours ago··Based on 12 sources

The CDN for everything on npm

Depends

Depends

Use it free for demos, prototypes, and quick script tags — it's dead simple and costs nothing.

Free npm CDN: perfect for demos, risky for production — repeated outages and phishing abuse documented.

Confidence: Medium

$0

Price

Open source, fully free

11.5%

Web usage share

of all websites, per w3techs

2,864,548

Websites tracked

BuiltWith tracking list

Value for money5

Completely free, open source

Ease of use5

Simplest way to get npm package into browser

Feature depth2

Just file serving; jsDelivr offers more

Support quality2

No SLA; outages left users stranded

Security posture2

Repeatedly abused for phishing campaigns

Pros

  • Completely free CDN covering every npm package²
  • Simplest way to get an npm package into a browser
  • Used by 11.5% of all websites11
  • Ideal for apps that run entirely in the browser¹

Cons

  • Multiple outages briefly broke thousands of websites³
  • 520 errors made it completely unusable for real projects
  • 175 malicious npm packages abused it for phishing
  • Devs warn against relying on third parties for critical infrastructure
  • Slow package loading times reported by users

Gotchas

  • highZero SLA or support — when it breaks, your site breaks with it
  • mediumMalicious npm packages serving phishing pages can ride on your unpkg references
  • mediumCommon fix for reliability is migrating to jsDelivr — editing URLs everywhere10
  • mediumFree service means no recourse or compensation during outages

Best for

  • Quick demos and prototypes
  • Open-source docs and playgrounds
  • Browser-only apps with no build step
  • One-off script tags for libraries

Not for

  • Production sites — outages have broken thousands
  • Anything needing uptime SLAs or support
  • Security-sensitive orgs worried about supply-chain abuse
  • High-traffic apps needing guaranteed edge performance

Companies that use it

  • Google
  • Microsoft
  • Facebook

Pricing

Free CDN

$0

  • Every npm package
  • Global content delivery
  • No paid tier exists

Security

No breach of unpkg itself found, but it is repeatedly abused as phishing infrastructure; one open-redirect report.

  • 175 malicious npm packages used unpkg for phishingCoordinated campaign served phishing pages to 100+ companies via unpkg-hosted content.
  • 24 npm packages abused unpkg mirrorsCampaign used unpkg mirrors to host fake Cloudflare pages.
  • Open redirect vulnerabilityResponsible-disclosure report OBB-3870005 filed against.

What users say

Users love the simplicity but repeatedly hit outages and warn against depending on it for anything important.

Don't rely on other people hosting important infrastructure
Reddit, r/webdev
Anyone else getting 520 errors trying to fetch packages from unpkg.com?
Reddit, r/sysadmin
Yeah unpkg isn't the most reliable CDN out there.
GitHub, stryker-mutator issue #215

Alternatives

Compare UNPKG with each alternative.

Self-hosted bundles

Bundle dependencies yourself; removes third-party risk entirely

Full analysis

Based on 20+ public sources; some are low-quality SEO sites, so findings weighted toward Reddit, GitHub, and security press.

Sources

  1. official
  2. official
  3. review
  4. review
  5. review
  6. security
  7. security
  8. security
  9. review
  10. review
  11. review
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.

    Comments

    One queue. No replies. Give a display name first. Limit: 7 comments per day.

    Save a name to write a comment.

    No comments yet.