Gathering detailed insights and metrics for handlebars
Gathering detailed insights and metrics for handlebars
Gathering detailed insights and metrics for handlebars
Gathering detailed insights and metrics for handlebars
handlebars-layouts
Handlebars helpers which implement layout blocks similar to Jade, Jinja, Nunjucks, Swig, and Twig.
handlebars-utils
Utils for handlebars helpers. Externalized from handlebars, to allow helpers to use the utils without having to depend on handlebars itself.
handlebars-loader
handlebars loader module for webpack
express-handlebars
A Handlebars view engine for Express which doesn't suck.
npm install handlebars
Typescript
Module System
Min. Node Version
Node Version
NPM Version
97.5
Supply Chain
99.3
Quality
81.9
Maintenance
100
Vulnerability
100
License
JavaScript (94.65%)
HTML (2.19%)
TypeScript (2.19%)
Shell (0.53%)
Ruby (0.24%)
Handlebars (0.13%)
Mustache (0.06%)
Total Downloads
0
Last Day
0
Last Week
0
Last Month
0
Last Year
0
MIT License
18,324 Stars
2,047 Commits
2,049 Forks
444 Watchers
17 Branches
188 Contributors
Updated on Jul 15, 2025
Latest Version
4.7.8
Package Id
handlebars@4.7.8
Unpacked Size
2.65 MB
Size
632.00 kB
File Count
118
NPM Version
9.5.1
Node Version
18.16.1
Published on
Aug 01, 2023
Cumulative downloads
Total Downloads
Last Day
0%
NaN
Compared to previous day
Last Week
0%
NaN
Compared to previous week
Last Month
0%
NaN
Compared to previous month
Last Year
0%
NaN
Compared to previous year
5
43
1
Handlebars.js is an extension to the Mustache templating language created by Chris Wanstrath. Handlebars.js and Mustache are both logicless templating languages that keep the view and the code separated like we all know they should be.
Checkout the official Handlebars docs site at https://handlebarsjs.com/ and the live demo at http://tryhandlebarsjs.com/.
See our installation documentation.
In general, the syntax of Handlebars.js templates is a superset of Mustache templates. For basic syntax, check out the Mustache manpage.
Once you have a template, use the Handlebars.compile
method to compile
the template into a function. The generated function takes a context
argument, which will be used to render the template.
1var source = "<p>Hello, my name is {{name}}. I am from {{hometown}}. I have " + 2 "{{kids.length}} kids:</p>" + 3 "<ul>{{#kids}}<li>{{name}} is {{age}}</li>{{/kids}}</ul>"; 4var template = Handlebars.compile(source); 5 6var data = { "name": "Alan", "hometown": "Somewhere, TX", 7 "kids": [{"name": "Jimmy", "age": "12"}, {"name": "Sally", "age": "4"}]}; 8var result = template(data); 9 10// Would render: 11// <p>Hello, my name is Alan. I am from Somewhere, TX. I have 2 kids:</p> 12// <ul> 13// <li>Jimmy is 12</li> 14// <li>Sally is 4</li> 15// </ul>
Full documentation and more examples are at handlebarsjs.com.
Handlebars allows templates to be precompiled and included as javascript code rather than the handlebars template allowing for faster startup time. Full details are located here.
Handlebars.js adds a couple of additional features to make writing templates easier and also changes a tiny detail of how partials work.
Block expressions have the same syntax as mustache sections but should not be confused with one another. Sections are akin to an implicit each
or with
statement depending on the input data and helpers are explicit pieces of code that are free to implement whatever behavior they like. The mustache spec defines the exact behavior of sections. In the case of name conflicts, helpers are given priority.
There are a few Mustache behaviors that Handlebars does not implement.
compat
flag must be set to enable this functionality. Users should note that there is a performance cost for enabling this flag. The exact cost varies by template, but it's recommended that performance sensitive operations should avoid this mode and instead opt for explicit path references.Handlebars has been designed to work in any ECMAScript 3 environment. This includes
Older versions and other runtimes are likely to work but have not been formally
tested. The compiler requires JSON.stringify
to be implemented natively or via a polyfill. If using the precompiler this is not necessary.
In a rough performance test, precompiled Handlebars.js templates (in the original version of Handlebars.js) rendered in about half the time of Mustache templates. It would be a shame if it were any other way, since they were precompiled, but the difference in architecture does have some big performance advantages. Justin Marney, a.k.a. gotascii, confirmed that with an independent test. The rewritten Handlebars (current version) is faster than the old version, with many performance tests being 5 to 7 times faster than the Mustache equivalent.
See release-notes.md for upgrade notes.
See FAQ.md for known issues and common pitfalls.
Have a project using Handlebars? Send us a pull request!
Handlebars.js is released under the MIT license.
9.8/10
Summary
Prototype Pollution in handlebars
Affected Versions
< 3.0.8
Patched Versions
3.0.8
9.8/10
Summary
Prototype Pollution in handlebars
Affected Versions
>= 4.0.0, < 4.3.0
Patched Versions
4.3.0
9.8/10
Summary
Prototype Pollution in handlebars
Affected Versions
< 4.7.7
Patched Versions
4.7.7
9.8/10
Summary
Remote code execution in handlebars when compiling templates
Affected Versions
< 4.7.7
Patched Versions
4.7.7
7.3/10
Summary
Arbitrary Code Execution in handlebars
Affected Versions
>= 4.0.0, < 4.5.2
Patched Versions
4.5.2
7.3/10
Summary
Arbitrary Code Execution in handlebars
Affected Versions
< 3.0.8
Patched Versions
3.0.8
8.1/10
Summary
Arbitrary Code Execution in Handlebars
Affected Versions
>= 4.0.0, < 4.5.3
Patched Versions
4.5.3
8.1/10
Summary
Arbitrary Code Execution in Handlebars
Affected Versions
< 3.0.8
Patched Versions
3.0.8
7.3/10
Summary
Prototype Pollution in handlebars
Affected Versions
< 3.0.7
Patched Versions
3.0.7
7.3/10
Summary
Prototype Pollution in handlebars
Affected Versions
>= 4.0.0, < 4.0.14
Patched Versions
4.0.14
7.3/10
Summary
Prototype Pollution in handlebars
Affected Versions
>= 4.1.0, < 4.1.2
Patched Versions
4.1.2
7.5/10
Summary
Regular Expression Denial of Service in Handlebars
Affected Versions
>= 4.0.0, < 4.4.5
Patched Versions
4.4.5
0/10
Summary
Arbitrary Code Execution in handlebars
Affected Versions
>= 4.0.0, < 4.5.3
Patched Versions
4.5.3
0/10
Summary
Arbitrary Code Execution in handlebars
Affected Versions
< 3.0.8
Patched Versions
3.0.8
0/10
Summary
Prototype Pollution in handlebars
Affected Versions
>= 4.0.0, < 4.5.3
Patched Versions
4.5.3
0/10
Summary
Prototype Pollution in handlebars
Affected Versions
< 3.0.8
Patched Versions
3.0.8
0/10
Summary
Remote code execution in Handlebars.js
Affected Versions
< 4.1.0
Patched Versions
4.1.0
0/10
Summary
Denial of Service in handlebars
Affected Versions
>= 4.0.0, < 4.4.5
Patched Versions
4.4.5
6.1/10
Summary
Cross-Site Scripting in handlebars
Affected Versions
< 4.0.0
Patched Versions
4.0.0
0/10
Summary
Moderate severity vulnerability that affects handlebars
Affected Versions
< 4.0.0
Patched Versions
4.0.0
Reason
security policy file detected
Details
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
license file detected
Details
Reason
Found 9/24 approved changesets -- score normalized to 3
Reason
dependency not pinned by hash detected -- score normalized to 2
Details
Reason
1 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 1
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
project is not fuzzed
Details
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Reason
56 existing vulnerabilities detected
Details
Score
Last Scanned on 2025-07-07
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More