unpkg.com
No paid content found
Categories: Other
The CDN for everything on npm
Related questions
More questions →What Are the Cache Performance Features of UNPKG?
UNPKG is a global content delivery network (CDN) for files published to npm, and its cache performance comes from two layers working together: immutable versioned URLs that browsers and edge nodes can cache for a long time, and a global edge network that serves repeated requests from a location near the user. The practical result is that a request for a pinned version like unpkg.com/[email protected]/umd/react.production.min.js can be served from cache instead of hitting npm's registry, while a request for a moving target like unpkg.com/react@latest/... is harder to cache because the underlying file can change.
Why Versioned URLs Cache Well
The URL structure unpkg.com/:package@:version/:file is the key mechanism. When you pin an exact version, the content behind that URL never changes — the same version of a package on npm is immutable. That makes the URL safe to cache aggressively at every layer: the browser, intermediate proxies, and UNPKG's own edge nodes.
By contrast:
unpkg.com/[email protected]/dist/preact.min.js— exact version, stable content, cache-friendly.unpkg.com/preact@latest/dist/preact.min.js— resolves to whatever the latest tag points to today, so the content can change when a new version is published.unpkg.com/react@^18/umd/react.production.min.js— a semver range, which can also resolve to a different file over time.
If you don't specify a version at all, UNPKG uses the latest tag by default, so unpkg.com/preact/dist/preact.min.js behaves like the latest case.
Practical takeaway: pin exact versions in production so you get the strongest caching and predictable content. Use latest or ranges only when you deliberately want to track new releases.
The Global Edge Network
UNPKG describes itself as a "fast, global" CDN, which means requests are handled by edge nodes distributed geographically rather than a single origin server. For a user in one region requesting a popular package, the file is likely already cached at a nearby edge node from previous traffic, so the response avoids a round trip to the registry.
This matters most for:
- Popular packages (React, Vue, Preact, Three.js) that see heavy traffic and stay warm in edge caches.
- Repeated requests across many users, where the first request populates the cache and later ones are served quickly.
Less popular or newly published packages may not be cached at every edge node yet, so the first request in a region can be slower than subsequent ones.
Cache Behavior You Should Plan Around
| URL pattern | Content stability | Caching outlook |
|---|---|---|
[email protected]/file.js |
Immutable | Best — safe to cache long-term |
pkg@latest/file.js |
Changes on new publish | Weaker — may be revalidated |
pkg@^1/file.js |
Changes within range | Weaker — may be revalidated |
pkg/file.js (no version) |
Follows latest |
Weaker — same as latest |
A few practical implications:
- Pin versions for production assets. This is the single biggest lever for cache performance and reproducibility.
- Expect first-request latency for cold packages. A package with little traffic may not be cached near your users yet.
- Don't rely on UNPKG for private or frequently changing content. It serves public npm packages, and moving targets undercut caching.
What UNPKG Does Not Change
UNPKG's caching is about delivery speed, not about bypassing npm. The files it serves are the published package contents on npm, so anything you'd change by republishing a version isn't something UNPKG's cache can fix — and republishing the same version isn't how npm versioning works anyway. If you need different content, you publish a new version and update your URL.
For most frontend use cases — loading a library via a <script> tag or an ES module import — pinning an exact version and letting UNPKG's edge network handle distribution gives you the best combination of speed and predictability.
What is UNPKG?
UNPKG is a fast, global content delivery network (CDN) for everything published on npm. You use it to load any file from any npm package directly in a browser or script by constructing a URL in the form unpkg.com/:package@:version/:file. It is most useful when you want to pull a dependency into a page or prototype without setting up a build step or installing anything locally.
How the URL works
Every UNPKG request maps to a file inside an npm package. The URL has three segments, and only the first is required:
| Segment | Meaning | Example |
|---|---|---|
:package |
The package name on npm | preact, react, three |
:version |
A version, npm dist-tag, or semver range | 10.26.4, latest, ^18 |
:file |
Path to a file inside the package | dist/preact.min.js |
Concrete examples from the site:
unpkg.com/[email protected]/dist/preact.min.js
unpkg.com/[email protected]/umd/react.production.min.js
unpkg.com/[email protected]/build/three.module.min.js
You can substitute any valid semver range or npm tag for the version:
unpkg.com/preact@latest/dist/preact.min.js
unpkg.com/react@^18/umd/react.production.min.js
If you omit the version entirely, the latest tag is used by default:
unpkg.com/preact/dist/preact.min.js
unpkg.com/vue/dist/vue.esm-browser.prod.js
Browsing and resolving files
If you don't know the exact file path, UNPKG helps you find it.
- Directory listings: add a trailing
/to a directory URL to see all files in it, e.g.unpkg.com/react/,unpkg.com/preact/src/, orunpkg.com/react-router/. - Older versions: include a version number to browse a specific release, e.g.
unpkg.com/react@18/orunpkg.com/react-router@5/. - Default entry point: if you omit the file path, UNPKG resolves the package's default entry. For many frontend-only packages like jQuery and GSAP, this is the
mainfield inpackage.json, sounpkg.com/jqueryandunpkg.com/gsapjust work.
How entry points resolve in modern packages
For packages that use the exports field, UNPKG resolves the file using the default export condition. If you publish a package like this:
{
"name": "my-package",
"exports": {
"default": "./dist/index.js"
}
}
you can load it with:
<script src="https://unpkg.com/my-package"></script>
The full exports spec is supported, including subpaths. Given:
{
"name": "my-package",
"exports": {
"./exp": {
"default": "./dist/exp.js"
}
}
}
you can load the subpath with:
<script src="https://unpkg.com/my-package/exp"></script>
Custom export conditions are supported through the ?conditions query parameter, which lets you load a different file based on environment or other conditions. For example, to fetch React using the react-server condition:
fetch("https://unpkg.com/react?conditions=react-server")
When to use it
UNPKG fits quick, no-build scenarios:
- No-build apps — drop a
<script>tag into an HTML file and start using a library. - Inline scripts — reference a package URL inside a script block or console snippet.
- Browser modules — load ESM builds directly with
importfrom a UNPKG URL.
If you need pinned, reproducible dependencies in production, prefer a versioned URL (or a lockfile-based bundler) rather than relying on latest, since the default tag can change when a package publishes a new release.
How UNPKG Resolves a Package's Default Entry Point
When you request a package from UNPKG without a file path, UNPKG resolves the file using the package's default entry point. For packages that use the exports field, it resolves using the default export condition. For older packages without exports, it falls back to the main field in package.json. If you want a specific file instead, include the path in the URL.
The URL pattern
UNPKG serves any file on npm through a URL of this shape:
https://unpkg.com/:package@:version/:file
| Segment | Meaning |
|---|---|
:package |
The package name on npm |
:version |
A version, npm dist-tag, or semver range (optional) |
:file |
Path to a file inside the package (optional) |
If you omit the version, the latest tag is used. If you omit the file path, UNPKG resolves the default entry point.
How the default entry point is chosen
The resolution depends on how the package declares its entry points.
Packages using exports
Modern packages declare entry points with the exports field. UNPKG resolves the file using the default export condition.
For example, given this package.json:
{
"name": "my-package",
"exports": {
"default": "./dist/index.js"
}
}
You can load the package with just the package name:
<script src="https://unpkg.com/my-package"></script>
Packages using main
For packages meant for frontend development that don't use exports — jQuery and GSAP are the examples UNPKG gives — the default entry point is the value of the main field in package.json.
https://unpkg.com/jquery
https://unpkg.com/gsap
Subpaths and custom conditions
The full exports spec is supported, including subpaths. If a package declares:
{
"name": "my-package",
"exports": {
"./exp": {
"default": "./dist/exp.js"
}
}
}
You can load that subpath directly:
<script src="https://unpkg.com/my-package/exp"></script>
Custom export conditions are supported through the ?conditions query parameter, which lets you load a different file based on the environment or other conditions. To fetch React using the react-server condition:
fetch("https://unpkg.com/react?conditions=react-server")
Browsing and pinning versions
Add a trailing / to a directory URL to see a listing of every file in that directory:
https://unpkg.com/react/
https://unpkg.com/preact/src/
To browse an older version, put the version in the URL:
https://unpkg.com/react@18/
https://unpkg.com/react-router@5/
You can also use any valid semver range or npm tag, such as preact@latest or react@^18.
Practical takeaways
- Omit the file path only when you trust the package's default entry point. If you need a specific build, name the file explicitly.
- Pin a version in production. A bare package name resolves to
latest, which can change without warning. - Use
?conditionswhen a package ships environment-specific builds and you need one that isn't the default. - Check the directory listing first if you're unsure which files a package ships — append
/to the package or version URL.
How to Load a File from an npm Package with UNPKG
Use a UNPKG URL in the form https://unpkg.com/:package@:version/:file. Put the npm package name in :package, a version, dist-tag, or semver range in :version, and the path to the file inside the package in :file. If you omit the version, UNPKG resolves the latest tag by default. If you omit the file path, UNPKG resolves the package's default entry point.
The URL format
https://unpkg.com/:package@:version/:file
| Segment | Meaning | Example |
|---|---|---|
:package |
The package name on npm | preact, react, three |
:version |
Package version, npm dist-tag, or semver range | 10.26.4, latest, ^18 |
:file |
Path to a file in the package | dist/preact.min.js |
Concrete examples from the UNPKG site:
https://unpkg.com/[email protected]/dist/preact.min.js
https://unpkg.com/[email protected]/umd/react.production.min.js
https://unpkg.com/[email protected]/build/three.module.min.js
Choosing a version
You are not limited to an exact version number. UNPKG accepts any valid semver range or npm tag:
https://unpkg.com/preact@latest/dist/preact.min.js
https://unpkg.com/react@^18/umd/react.production.min.js
If you leave the version out entirely, the latest tag is used:
https://unpkg.com/preact/dist/preact.min.js
https://unpkg.com/vue/dist/vue.esm-browser.prod.js
For production pages, pin an exact version so a new release cannot change what your users load. Use latest or a range only when you deliberately want updates.
Browsing a package
Add a trailing / to a directory URL to see a listing of all files in that directory:
https://unpkg.com/react/
https://unpkg.com/preact/src/
https://unpkg.com/react-router/
To browse an older version, include the version in the URL:
https://unpkg.com/react@18/
https://unpkg.com/react-router@5/
When you omit the file path
If you do not specify a file, UNPKG resolves the file based on the package's default entry point.
- For many frontend-only packages such as jQuery and GSAP, this is the
mainfield inpackage.json:
https://unpkg.com/jquery
https://unpkg.com/gsap
- For modern packages that use the
exportsfield, UNPKG resolves using thedefaultexport condition. Given thispackage.json:
{
"name": "my-package",
"exports": {
"default": "./dist/index.js"
}
}
you can load the package with:
<script src="https://unpkg.com/my-package"></script>
The full exports spec is supported, including subpaths. With this package.json:
{
"name": "my-package",
"exports": {
"./exp": {
"default": "./dist/exp.js"
}
}
}
you can load the exp subpath with:
<script src="https://unpkg.com/my-package/exp"></script>
Custom export conditions
You can request a different file based on environment or other conditions with the ?conditions query parameter. For example, to fetch React using the react-server condition:
fetch("https://unpkg.com/react?conditions=react-server")
Common pitfalls
- Missing file path on a package with no usable entry point. If the package's
mainorexportsdoes not point to a browser-ready file, the bare URL may return something you cannot load in a<script>tag. Add the explicit file path instead. - Relying on
latestin production. A new publish can silently change the file your page loads. Pin the version. - Wrong file for the environment. A CommonJS build will not run as a browser module. Check the package's
distorbuilddirectory for the ESM or UMD file you need. - Assuming a directory URL returns a file. A trailing
/gives you a file listing, not the package entry point.
Website Overview
An established domain and managed infrastructure suggest continuity of operations and may support dependable delivery, although neither guarantees service quality.
Domain and Registration
Registered in 2016, this domain has about 10 years of history. That suggests continuity, although ownership and purpose may have changed. Transfer-protection status is present, helping reduce the risk of unauthorized domain transfers. The registrar is Cloudflare, Inc., a widely used domain service provider. The domain uses the common .com extension, which is not an independent safety signal.
DNS and Email
The lowest TTL is 14 seconds, supporting rapid record changes at the cost of more frequent lookups. Nameservers are provided by Cloudflare, indicating managed DNS hosting. MX records point to the Cloudflare Email Routing email service. No CNAME was found; the observed records resolve directly to addresses. SPF and DMARC are configured. DKIM status is unknown.
TLS and Certificates
The public key uses EC with 256 bits. The server supplied a complete certificate chain. No organization name is present in the certificate; the available fields are consistent with domain validation. The certificate was issued within the Google Trust Services cloud or CDN ecosystem. The certificate's total validity is about 90 days, consistent with a short renewal cycle.
HTTP and Browser Security
The response lacks these common security headers: CSP, Referrer-Policy, Permissions-Policy, clickjacking protection. No X-Powered-By header was found, reducing one common source of backend fingerprinting information. The cf-ray response header indicates a CDN or caching proxy in the delivery path. No obvious internal addresses or debug information were found in the headers. The Server header identifies cloudflare without an exact version.
Technology Stack Analysis
The public page identifies React, Bootstrap, Google Analytics, Cloudflare without precise versions, leaving fewer clues for version-specific scanning.
Search and Social Sharing
No homepage canonical URL was detected. If duplicate URLs exist, consolidation may be less explicit. Twitter Card metadata is configured. The title has 5 characters, within a common display range. A meta description is present, with 29 characters. The observed directives allow indexing and link following.
Hosting and Email
Pages, Search and Sharing
| Meta description | The CDN for everything on npm |
|---|---|
| Canonical URL | Not detected |
| Language | English (default) |
| Twitter Card | summary_large_image |
Social Sharing Preview
10 fieldsrobots.txt (opens in a new tab)
0 rulesNo rules found
No matching rules.
Sitemaps
0No sitemaps found
Registration details RDAP / WHOIS
| Registrar | Cloudflare, Inc. |
|---|---|
| Registered | 2016-01-06 |
| Expires | 2027-01-06 |
| Domain status | client transfer prohibited |
| Nameservers | alexia.ns.cloudflare.com、weston.ns.cloudflare.com |
| DNSSEC | unsigned |
DNS records
| Type | Name | Value | TTL | Priority |
|---|---|---|---|---|
| A | unpkg.com | 104.18.0.22 | 14 | — |
| A | unpkg.com | 104.18.1.22 | 14 | — |
| AAAA | unpkg.com | 2606:4700::6812:116 | 69 | — |
| AAAA | unpkg.com | 2606:4700::6812:16 | 69 | — |
| MX | unpkg.com | route3.mx.cloudflare.net | 300 | 6 |
| MX | unpkg.com | route2.mx.cloudflare.net | 300 | 36 |
| MX | unpkg.com | route1.mx.cloudflare.net | 300 | 73 |
| NS | unpkg.com | alexia.ns.cloudflare.com | 86400 | — |
| NS | unpkg.com | weston.ns.cloudflare.com | 86400 | — |
| TXT | unpkg.com | v=spf1 include:_spf.mx.cloudflare.net ~all | 300 | — |
| DMARC | _dmarc.unpkg.com | v=DMARC1; p=none; | 300 | — |
TLS and certificates
| Assessment | Normal configuration |
|---|---|
| Supported protocols | TLSv1.2、TLSv1.3 |
| Negotiated protocol | TLSv1.3 |
| Certificate subject | unpkg.com |
| Issuer | Google Trust Services |
| Valid until | 2026-12-07T19:43 · Remaining when checked: 71 days |
| Verification details | Certificate trust: Passed · Hostname match: Passed |
HTTP response headers
| Header | Value |
|---|---|
| content-type | text/html; charset=utf-8 |
| cache-control | public, max-age=60, s-maxage=300 |
| server | cloudflare |
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Identified technologies
Recent Updates
- Website images
- Screenshots
- Network details
- Website Technologies
- Pages and Search Information
- HTTP Response Information
- TLS and certificates
- DNS Information
- Domain Registration
- Website profile
- Website Description
- Website Name
- Website profile
- Website Description
- Website Name
User reviews (0)