
Security News
November CVEs Fell 25% YoY, Driven by Slowdowns at Major CNAs
November CVE publications fell 25% YoY even as 2025 totals rose, showing how a few major CNAs can swing “global” counts and skew perceived risk.
@10up/scripts
Advanced tools
A collection of bundled scripts for 10up development.
npm install --save-dev @10up/scripts
10up-scripts build
Builds CSS and JavaScript files. This uses the 10up configuration for Webpack.
10up-scripts start
Builds CSS and JavaScript and watches files for changes.
10up-scripts format-js
Fixes JavaScript formatting issues via ESLint with 10up configuration.
10up-scripts lint-js
Runs ESLint with 10up configuration
10up-scripts lint-style
Runs Stylelint with 10up configuration.
10up-scripts test-unit-jest
Runs Jest on current project.
10up-scripts check-engines
Verify the Node and npm satisfy minimum package.json versions.
Project is a fork of wp-scripts
Active: 10up is actively working on this, and we expect to continue work for the foreseeable future including keeping tested up to the most recent version of WordPress. Bug reports, feature requests, questions, and pull requests are welcome.
FAQs
Collection of reusable scripts for 10up development.
The npm package @10up/scripts receives a total of 33 weekly downloads. As such, @10up/scripts popularity was classified as not popular.
We found that @10up/scripts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
November CVE publications fell 25% YoY even as 2025 totals rose, showing how a few major CNAs can swing “global” counts and skew perceived risk.

Security News
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.

Research
/Security News
We spotted a wave of auto-generated “elf-*” npm packages published every two minutes from new accounts, with simple malware variants and early takedowns underway.