svelte
Cybernetically enhanced web apps
About
Cybernetically enhanced web apps
What detecting svelte tells you about a site
svelte signals a site built with the compiler-first framework that ships little-to-no runtime, so the bundle is usually noticeably smaller than an equivalent React app. Its presence often means SvelteKit is the meta-framework, and that the team optimised for bundle size and runtime performance.
Why the exact svelte version matters
Svelte 5 rewrote reactivity around runes (`$state`, `$derived`), a fundamental change from the implicit reactivity of Svelte 3/4. The exact bundled version tells you which reactivity model the codebase uses and whether it has migrated to the current generation — a meaningful signal of how actively the project is maintained.
svelte in a real-world stack
When you find svelte in a bundle, it rarely travels alone. SvelteKit for routing and SSR; relatively few peripheral libraries, since Svelte's standard library covers a lot in-house.
Quick facts
npm install svelteThis package powers Svelte
The svelte package is the canonical implementation of Svelte. Sourcemap Explorer uses this exact npm package as the framework-level fingerprint when it flags Svelte on a page — both via the bundled node_modules/svelte/ source paths and via the embedded package.json inside the JavaScript sourcemap.
What svelte pulls in
svelte declares 16 direct dependencies — each one also rides into any bundle that ships svelte, so they are detection targets too. Reading them is a quick way to understand the package's real footprint .
How Sourcemap Explorer detects svelte
svelte ships as v5.56.8, published 2026-07-24 and carries 16 direct dependencies, 1,088 versions on the registry. Those exact numbers are the footprint Sourcemap Explorer matches when svelte rides inside a deployed bundle — here is how the detection works.
We catch svelte from two complementary signals: bundled source paths and the embedded package.json. Modern bundlers (webpack, Vite, esbuild, Rollup, Turbopack) preserve the original node_modules/svelte/ paths inside the JavaScript sourcemap's sources[] array — that's the canonical signal. When the matching package.json is also captured in sourcesContent[], we read the exact version field — patch number included. No regex guessing, no version inference.
- 1
Confirm the site exposes sourcemaps
In DevTools Network, check the response headers of any application script for `SourceMap` or `X-SourceMap`. Failing that, fetch the script's last 4 KB and look for a `//# sourceMappingURL=` comment — that map is where the `svelte` paths live.
- 2
Find the package in the bundle
Open DevTools → Network → reload. Click any application script and look at its sourcemap. Inside, search `sources[]` for entries matching `node_modules/svelte/` — every match confirms the package is bundled. The matching `sourcesContent[i]` for `node_modules/svelte/package.json` gives you the exact installed version.
- 3
Read the version directly from package.json
Run `jq -r '. as $m | $m.sources | to_entries[] | select(.value | endswith("node_modules/svelte/package.json")) | $m.sourcesContent[.key] | fromjson | .version' bundle.js.map`. Sourcemap Explorer automates the same query in the popup.
Major releases of svelte
When each major version first landed. Major bumps are where breaking changes live, so this timeline is the fastest way to date the svelte version a site actually ships against the ecosystem.
Recent security advisories for svelte
The 5 most recent advisories affecting some versions of svelte, aggregated from OSV.dev (GitHub Advisory + CVE data). A listing here doesn't mean the version a given site ships is affected — each advisory applies to a specific version range. Sourcemap Explorer reads the exact bundled version so you can check it against these ranges.
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
Svelte: ReDoS in `<svelte:element>` Tag Validation
Svelte SSR vulnerable to cross-site scripting via spread attributes
Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
Recent versions
svelte README
Live mirror of the GitHub README, for reference. Updated whenever the repo's default branch changes.
What is Svelte?
Svelte is a new way to build web applications. It's a compiler that takes your declarative components and converts them into efficient JavaScript that surgically updates the DOM.
Learn more at the Svelte website, or stop by the Discord chatroom.
Getting started
You can play around with Svelte in the tutorial, examples, and REPL.
When you're ready to build a full-fledge application, we recommend using SvelteKit:
npx sv create my-app
cd my-app
npm install
npm run dev
See the SvelteKit documentation to learn more.
Changelog
The Changelog for this package is available on GitHub.
Supporting Svelte
Svelte is an MIT-licensed open source project with its ongoing development made possible entirely by fantastic volunteers. If you'd like to support their efforts, please consider:
Funds donated via Open Collective will be used for compensating expenses related to Svelte's development.
FAQ
What is svelte used for?
Cybernetically enhanced web apps
How can I tell if a website is using svelte?
Open the page in Chrome with the Sourcemap Explorer extension installed and read the Stack tab. We catch `svelte` from two complementary signals: `node_modules/svelte/` paths inside the JavaScript sourcemap, and the embedded `package.json` we read for exact-version detection. Without the extension you can do the same lookup manually in DevTools — the steps are listed in the "How Sourcemap Explorer detects" section above.
How do I find out which version of svelte a website is running?
Read it straight from the site's JavaScript sourcemap. When a build ships source maps, the bundled `svelte/package.json` carries the exact `version` string — Sourcemap Explorer extracts it in one click on the Stack tab, and you can do it by hand in DevTools by opening the `.map` file and searching for `node_modules/svelte/package.json`. That is far more reliable than inferring the version from an asset-hash or a `?ver=` query string, which is all surface-level detectors have to go on. The current npm release is 5.56.8, but real deployments frequently run an older pinned version — which is exactly why reading the bundled number matters.
What is the latest version of svelte?
5.56.8, as published on the npm registry. The "Recent versions" table on this page lists the most recent 8 releases with their release dates. Sourcemap Explorer reports the version actually bundled into a site, which can lag the latest release by months on real-world deployments.
Is svelte actively maintained?
Very actively maintained — the last release shipped within the past three months. The last published release was 2026-07-24. Source code: https://github.com/sveltejs/svelte.
What is the relationship between svelte and Svelte?
svelte is the canonical npm package for Svelte. Sourcemap Explorer treats finding `svelte` in a bundle as the framework-level signal that Svelte is on the page, and the page you're reading is the canonical Sourcemap Explorer entry for the package itself.
Does svelte have known security vulnerabilities?
5 recent advisories affecting some versions of svelte are listed in the "Recent security advisories" section above, aggregated from OSV.dev (GitHub Advisory + CVE data). Whether a particular site is exposed depends entirely on the exact version it ships — each advisory applies to a specific version range, not to the package as a whole. That is why the precise bundled version matters: Sourcemap Explorer reads the version a site actually runs, so you can check it against the affected ranges instead of assuming the latest release is what's deployed.
Where can I read more?
Project homepage: https://svelte.dev. Source code: https://github.com/sveltejs/svelte. Published on npm: https://www.npmjs.com/package/svelte. Licensed as MIT.
Keep reading on Sourcemap Explorer
Practical guides
Detection deep dives
Alternative tools
Detected by Sourcemap Explorer
When a bundle ships sourcemaps, we read the embedded package.json for svelte and report the precise version (the registry's latest is v5.56.8, published 2026-07-24; the bundled copy is often older). Without sourcemaps, an import / require in the page's scripts is enough to flag it.