esm.sh (esm-dev)
owned by Independent · esm.sh · 3 vendors
esm.sh is an open-source, no-build JavaScript CDN for modern web development, allowing developers to import ES modules (ESM) from NPM, JSR, and GitHub directly via URL in browsers and Deno without any build steps. It is powered by Cloudflare's global network and uses esbuild to transform and bundle packages on the fly. The project is maintained by an independent developer (@ije) under the MIT license and funded through GitHub Sponsors and Open Collective.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 4
Technology vendors
- Cloudflare, Inc. — Technology — United States
- Lazysizes — Technology — Germany
- MarketingPlatform ApS — Media & Marketing — Denmark
Insights
Last updated 2026-08-10 · revision 3
3 direct vendors, 89 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Germany: 1
- United States: 1
Subvendors by controlling owner country (sample)
- Norway: 2
- Switzerland: 1
- Brazil: 1
Migration Readiness: 10/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
esm.sh exhibits very high migration readiness, scoring 95. Its architecture is highly cloud-native and containerized, with a self-hostable Docker image (ghcr.io/esm-dev/esm.sh) and support for S3-compatible storage backends, making it exceptionally portable across various cloud providers or on-premise infrastructure. The modern tech stack, including Go, Rust, and WebAssembly, further enhances its adaptability to contemporary deployment environments. Data residency requirements are minimal; as a public CDN, data is cached globally via Cloudflare, and origin data resides on npm's servers, with users typically not specifying residency for their content. This significantly simplifies any migration efforts. The regulatory environment is also favorable, with no complex public certifications (like SOC2 or ISO 27001) and NIS2 compliance deemed not applicable, reducing compliance hurdles during a migration. Vendor lock-in is low due to the open-source nature and self-hosting capabilities, which allow for configuration of alternative storage backends and NPM registries. While "Total Vendors: 0" is contradictory with "Total Services: 6" and "Vendor Geographic Diversity: 3 unique countries", the ability to self-host and configure key dependencies (like storage) provides substantial flexibility, mitigating potential lock-in to specific external services like Cloudflare or NPM for core functionality. The primary unknown is the lack of financial stability data, which could impact the ability to fund a large-scale migration, though the lean and portable architecture suggests a lower cost of migration compared to monolithic legacy systems.
Compliance
8 in-scope frameworks identified; showing 3.
Supply Chain Security — Assessment Required
esm.sh acts as a critical software supply chain intermediary, serving npm, JSR, and GitHub packages as ES modules directly to browsers and runtime environments. A compromise of esm.sh (e.g., malicious code injection, dependency confusion attack, or CDN cache poisoning) could affect millions of downstream applications globally. US Executive Order 14028 (Improving the Nation's Cybersecurity) and NIST Secure Software Development Framework (SSDF) emphasize software supply chain security. The risk is high because: (1) esm.sh is a single point of failure for many applications; (2) no Software Bill of Materials (SBOM), code signing, or Subresource Integrity (SRI) generation is currently implemented (the FAQ notes SRI support is 'being worked on'); (3) no documented security review process for served packages; (4) the open-source maintainer model means security depends on a very small team.
Evidence: https://esm.sh, https://github.com/esm-dev/esm.sh, https://www.nist.gov/system/files/documents/2022/09/14/SSDF_1.1_final.pdf, https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/
Cloudflare Terms of Service & Data Processing Addendum — Assessment Required
esm.sh explicitly relies on Cloudflare as its CDN infrastructure provider. Cloudflare processes all request data on behalf of esm.sh. For GDPR compliance, esm.sh must have a valid Data Processing Agreement (DPA) with Cloudflare as a data processor. No evidence of such a DPA or compliance with Cloudflare's data processing terms has been publicly documented by esm.sh. This is a critical gap in the data processing chain, particularly for EU user data.
Evidence: https://esm.sh, https://www.cloudflare.com/trust-hub/compliance-resources/, https://www.cloudflare.com/cloudflare-customer-dpa/
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (Regulation 2024/2847), which entered into force in December 2024 with phased application through 2027, introduces cybersecurity requirements for products with digital elements placed on the EU market. Open-source software components used in commercial contexts may fall within scope. esm.sh serves as a CDN for open-source JavaScript packages and could be considered a 'product with digital elements' or a component thereof. The risk is medium because: (1) the CRA has specific carve-outs for open-source software developed without commercial intent; (2) esm.sh's status as a free, open-source service may qualify for exemptions; (3) however, the commercial use of esm.sh by paying sponsors and enterprise users may complicate the open-source exemption analysis.
Evidence: https://esm.sh, https://github.com/esm-dev/esm.sh, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847
Financials
Financial Resilience Score: 4/10
esm.sh is not a company but an open-source project with no legal entity, no audited financials, and no commercial revenue model. Its financial resilience must be assessed through the lens of vendor-continuity risk rather than traditional credit metrics. The project benefits from an extremely low cost structure, as Cloudflare absorbs the largest expense (bandwidth) through in-kind sponsorship, and there is essentially no payroll overhead since the project is maintained by a single individual. However, the project faces significant fragility. It depends entirely on voluntary donations via GitHub Sponsors (only 1 active sponsor publicly listed) and Open Collective, plus in-kind infrastructure from Cloudflare. Key-person risk is severe, with a single maintainer (Je Xia / @ije) responsible for the entire project. Loss of Cloudflare's sponsorship would create an immediate, unmanageable bandwidth cost at ~8.84 billion module requests per month. The lack of a legal entity also prevents enterprise contracting and institutional sponsorship. Its resilience score reflects strong operational traction and low costs offset by extreme concentration risks.
Key strengths: Cloudflare sponsors bandwidth (largest cost line eliminated), Minimal headcount overhead (single maintainer), High usage traction: ~8.84 billion modules served in last 30 days, MIT-licensed and self-hostable (code survives even if hosted service ceases), High-profile backers including Deno, Val Town, Guillermo Rauch, Anthony Fu, Entrenched position in JavaScript/Deno ecosystem
Risk factors: Key-person/bus-factor risk: single maintainer (@ije), No commercial revenue model, depends entirely on donations, Concentration on Cloudflare for infrastructure sponsorship, Only 1 active GitHub sponsor publicly listed, No legal entity (no liability shield, no enterprise contracting), No audited books or financial statements, No SLA or contract counterparty for users
Revenue by geography
- Global (via Cloudflare edge network): 100%
Revenue by product/service
- esm.sh CDN (module transformation and delivery): 100%
Workforce by country
- Unknown (likely China): 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.