Popper.js Project

Open Source · popper.js.org · 5 vendors

Popper.js is an open-source JavaScript library that provides a robust positioning engine for UI elements like tooltips, popovers, and dropdowns. It helps developers accurately place these "popper" elements relative to a reference element, handling complex layout scenarios and offering a modular, extensible architecture. It is now part of the Floating UI project.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 5 sub-vendors.

Insights

Last updated 2026-07-29 · revision 6

5 direct vendors, 97 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The Popper.js Project exhibits high migration readiness, primarily due to its modern, modular, and open-source technical foundation. The project's tech stack, including JavaScript (ES Modules), TypeScript, GitHub Actions for CI/CD, and tools like Rollup and Jest, is highly flexible and portable. The existence of 'Floating UI' as an official successor project indicates a proactive approach to evolving its core technology, making future transitions smoother. A significant advantage for migration is the complete absence of complex regulatory compliance requirements (GDPR, NIS2, HIPAA, SOC2, ISO 27001, ISAE 3000 are all 'Not Applicable' with 'Low' risk) and no specific data residency requirements. This drastically reduces the legal and technical overhead typically associated with migrating services or data. While the project reports 'Total Vendors: 0', it relies on critical services like GitHub, npm, and Netlify. Although switching these platforms would require effort, they are standard open-source ecosystem components, and alternatives exist, suggesting a manageable level of practical lock-in rather than contractual complexity. The client-side nature of the JavaScript library also inherently simplifies migration compared to server-side applications. The primary challenge for any significant migration effort would be the project's small estimated annual budget ($8,955), which could limit the financial resources available for large-scale platform shifts or re-architecting, despite the high technical flexibility.

Compliance

3 in-scope frameworks identified; showing 3.

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (Regulation 2024/2847), adopted in October 2024 and entering into force progressively through 2027, introduces cybersecurity requirements for products with digital elements placed on the EU market. Critically, Article 16 and Recital 18 address open-source software: OSS developed entirely outside commercial activity is generally exempt, but OSS that is monetized or integrated into commercial products by its maintainers may face obligations. Risk is Medium because: (1) Popper.js/Floating UI is widely integrated into commercial products (Bootstrap, etc.), (2) the boundary between 'non-commercial' OSS and commercially-relevant OSS under CRA is still being clarified by the European Commission, (3) if any maintainer receives commercial compensation, CRA obligations could attach. The risk is not High because the project itself does not sell products.

Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847, https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act, https://openssf.org/blog/2024/10/23/the-eu-cyber-resilience-act-and-open-source-software/

npm Registry — Assessment Required

Popper.js is distributed via npm (npmjs.com/package/@popperjs/core) with hundreds of millions of downloads. npm has implemented security policies including 2FA requirements for maintainers of high-impact packages, provenance attestation, and supply chain security requirements. The risk is Medium because: (1) the package has extremely high downstream impact (used by Bootstrap, major frameworks), (2) supply chain attacks on npm packages are an active threat vector, (3) it is unclear whether current maintainers have fully implemented all npm security best practices (2FA, provenance signing, etc.). A compromised package could affect millions of downstream applications.

Evidence: https://www.npmjs.com/package/@popperjs/core, https://docs.npmjs.com/about-two-factor-authentication, https://openssf.org/, https://securityscorecards.dev/

Open Source License Compliance — Compliant

Popper.js is distributed under the MIT License, one of the most permissive and widely accepted open-source licenses. The project consistently applies the MIT License across all versions and the successor Floating UI project. License compliance risk is minimal as the MIT License imposes only attribution requirements on downstream users, not on the project itself. The project itself is the licensor, so it is inherently compliant with its own license terms.

Evidence: https://github.com/popperjs/popper-core/blob/master/LICENSE.md, https://www.npmjs.com/package/@popperjs/core, https://opensource.org/licenses/MIT

Financials

Financial Resilience Score: 6/10

Popper.js is not a company but an open-source JavaScript library distributed under the MIT license, so traditional financial resilience analysis is not applicable. However, assessed as a project's sustainability and dependency risk, it demonstrates moderate resilience. Its massive adoption footprint—tens of millions of weekly npm downloads across the Popper/Floating UI family, and integration into major frameworks like Bootstrap 4/5 and Material UI—provides strong ecosystem stability and low abandonment risk. The successful transition to the successor project Floating UI, led by the same core maintainers, further mitigates continuity risk. On the risk side, the project has no revenue model, no formal governance entity, no treasury, and no board. Sustainability depends on volunteer time and ad-hoc sponsorships (GitHub Sponsors, Open Collective, or maintainer employers). Key-person risk is elevated since a small number of core maintainers historically carry most of the work. Popper v1 and v2 are effectively in maintenance mode, meaning existing users will eventually need to migrate to Floating UI. For counterparty/supply-chain purposes, existing deployments are reasonably safe given ubiquity and permissive licensing, but new projects should adopt Floating UI instead.

Key strengths: Massive adoption with tens of millions of weekly npm downloads across Popper/Floating UI family, Dependency of major frameworks including Bootstrap 4/5 and Material UI, Active successor project (Floating UI) led by same core maintainers reduces abandonment risk, Permissive MIT license eliminates vendor lock-in and licensing revenue risk, Global community contributions via GitHub reduce single-maintainer risk

Risk factors: No revenue model; sustainability depends on volunteer time and sponsorships, Key-person risk from small number of core maintainers, Popper v1 and v2 in maintenance mode, requiring eventual user migration to Floating UI, No formal governance entity, treasury, board, or legal protection (unlike OpenJS Foundation projects), No legal entity registered in any national company register

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report