svg/svgo
56.4
Weak · 1 October 2026
14.4k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
SVGO is a command-line and library tool for optimizing SVG files by reducing their file size through a configurable plugin-based pipeline. It parses SVG input, applies transformations such as style cleanup and path optimization, and outputs the minimized result via standard output or files. The system supports both programmatic API usage and CLI workflows, handling single files, directories, and stdin input.
How it got here
2012 — SVGO v4 architecture rewrite
6 changes.
The project underwent a major overhaul to version 4.0.0, rewriting the core library, plugin system, and CLI to adopt an ESM-first architecture with pnpm, Vitest, and Rollup. This period focused on replacing legacy components with a new SAX-based parser, visitor-based plugin API, and modern tooling to improve type safety and developer experience.
2017–2021 — Comprehensive test suite expansion
7 changes.
This period focused on significantly expanding the project's test coverage by adding integration tests for the CLI, browser, and CommonJS environments. The team migrated the plugin tests to Vitest and established a robust suite of fixtures and assertions to validate core optimization behaviors, configuration loading, and security against attacks like the billion laughs.
2024–2026 — ESM migration and test infrastructure overhaul
6 changes.
The project migrated its CLI entry point to ES modules and upgraded the SAX parser, while introducing a build script to manage version constants. Significant effort was dedicated to rebuilding the regression testing system with a worker-based architecture for better performance and adding type tests for the svgo-node module. Internal utilities were also optimized through lazy invocation to improve initialization efficiency.
Features
Export version constant via build script
A new build script (scripts/sync-version.js) has been added to automatically generate a version constant. This script reads the version from package.json and writes it to lib/version.js as an exported constant, making the current version available to consumers of the library.
scripts · high confidence
Behavioural changes
CLI entry point converted to ES modules
The command-line interface entry point (bin/svgo.js) has been rewritten to use ES module syntax (import statements) instead of CommonJS. This change aligns the CLI tool with the project's broader migration to ECMAScript modules while maintaining compatibility with existing usage patterns.
bin · high confidence
Plugins refactored to use a new visitor-based API and modern JavaScript standards
The plugin system has been rewritten to use a new visitor-based API, replacing the previous traversal model. This change includes migrating the codebase to ECMAScript modules (ESM) while preserving CommonJS compatibility, and adding TypeScript type definitions for the plugins. The refactoring also introduces a new \preset-default\ plugin configuration and updates internal utilities like \\_collections\, \\_path\, and \\_transforms\ to support the new architecture, ensuring more consistent and maintainable plugin behavior.
plugins · high confidence
SAX library upgraded to 1.6.1 with API changes
The project has upgraded the SAX XML parser to version 1.6.1. This update removes the \SAXStream\ class and the \createStream\ factory function from the public API, meaning users can no longer use these stream-based utilities and must rely on the core \SAXParser\ for XML parsing.
patches · high confidence
SVGO CLI and plugin engine rewritten for ESM and Commander.js
The SVGO command-line interface has been completely rewritten to use ES modules and the Commander.js library, replacing the previous coa-based implementation. This change introduces new CLI options including --exclude for folder filtering, --eol and --final-newline for output formatting, and --show-plugins to list available plugins. The underlying plugin engine now supports presets and visitor-based plugins, and the CSS selection logic uses a custom adapter to work with the new XAST node structure.
lib/svgo · high confidence
SVGO v4 core rewritten with new parser, path handling, and style engine
The library core has been completely rewritten for v4, introducing a new SAX-based SVG parser that provides detailed error reporting with line/column positions, a dedicated path data parser and stringifier that correctly handles scientific notation and arc flags, and a new CSS style engine that computes styles from inline attributes, style sheets, and inheritance with caching. The optimization pipeline now uses a centralized \builtinPlugins\ registry and a \preset-default\ configuration, while the stringifier supports configurable indentation, line endings (LF/CRLF), and final newlines. This is a major behavioral change that may affect output formatting and plugin configuration syntax.
lib · high confidence
SVGO v4.0.0: Major overhaul with pnpm, Vitest, and ESM-first architecture
SVGO has been upgraded to version 4.0.0, introducing significant changes to the development environment and runtime architecture. The project has migrated from Yarn to pnpm for package management and switched its test runner from Jest to Vitest. The codebase has been converted to use ECMAScript modules (ESM) as the primary format while preserving CommonJS compatibility for consumers. Additionally, the build system now utilizes Rollup for bundling, and the project enforces Unix-style line endings and modern linting configurations via ESLint flat config. These changes improve build consistency, type safety, and developer experience.
(repo-wide) · high confidence
Fixes
Fix: Lazy invocation of mapNodesToParents
The \mapNodesToParents\ utility function in \lib/util\ is now invoked lazily. This change, combined with the introduction of the \visit\ helper for recursive node traversal, ensures that the mapping of nodes to their parents is computed only when needed, potentially improving performance by avoiding unnecessary processing during initialization.
lib/util · medium confidence
Test coverage
Added CLI integration tests for SVG optimization workflows; Added CLI integration tests using Vitest; Added browser and CommonJS integration tests; Added comprehensive test suite for SVGO core optimizations; Added empty test file for COA folder; Added test fixtures for config loader validation; Added tests for SVG parsing and character reference validation; Added type tests for svgo-node module; Migrate plugin tests to Vitest; New regression test infrastructure with worker-based optimization and comparison.
Dependencies
SVGO 4.1.0 release with pnpm migration and dependency updates
SVGO has been updated to version 4.1.0, introducing a migration to the pnpm package manager (v10.34.5) and requiring Node.js 16 or later. The release upgrades core dependencies including commander to v11, css-select to v6, css-tree to v3, and csso to v5, while also updating development tools such as ESLint to v10, Rollup to v4, and Vitest to v4.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 59 → 56 (-2.5)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 45 → 45 (+0.0)
- Architecture 100 → 100 (+0.1)
- Maturity 64 → 64 (+0.3)
- Readiness 72 → 54 (-18.3)
- Security 79 → 82 (+2.9)
- Performance 100 (new)
Resolved (6)
- Documentation: no architecture or design documentation (README.md)
- Hotspot: plugins/convertPathData.js (plugins/convertPathData.js)
- Hotspot: plugins/inlineStyles.js (plugins/inlineStyles.js)
- Hotspot: plugins/removeAttrs.js (plugins/removeAttrs.js)
- Off-boarding risk: anonymized user #1
- Repeated repair: test/regression/compare-worker.js (test/regression/compare-worker.js)
New (6)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
svg/svgo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e4cb29bebcc9820ac979dfc05106b512cc5de986 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.