Available worldwide

What is JSR?

An open-source package registry for JavaScript and TypeScript that publishes ECMAScript modules natively. It works across multiple JavaScript runtimes including Node.js, Deno, Bun, and Cloudflare Workers, with built-in TypeScript support, automatic documentation generation, and interoperability with npm packages.

Independently observed

JSR pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
FreeFree tier

Free and open-source

Public

Free
Free

Free public package registry

  • Publish packages
  • ECMAScript modules
  • Automatic API documentation
  • TypeScript support
  • Cross-runtime compatibility

What JSR does

The capabilities that matter for package registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Core
Role
Public registry
Ecosystem
Ecosystem / language
Polyglot
Deployment
Deployment
SaaS
Formats
Package formats supported
Single ecosystem
Hosting
Private / scoped packages
Upstream proxy / caching
-
Resolution
Lockfile / deterministic installs
-
Workspaces / monorepo
-
Content-addressable store
-
Supply chain
Supply-chain integrity
Vulnerability / licence scanning
-
Licensing
Openness
Open-source
Pricing
Pricing model
Free / OSS
Independently observed

Platform & deployment

Independently observed
Platforms
  • Web
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (7)

Independently observed
  • Node.js
  • Deno
  • Bun
  • Cloudflare Workers
  • npm
  • Algolia
  • GitHub

Security & compliance

Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality

JSR FAQ

Common questions about JSR, answered from independent, dated evidence.

What is JSR?

An open-source package registry for JavaScript and TypeScript that publishes ECMAScript modules natively. It works across multiple JavaScript runtimes including Node.js, Deno, Bun, and Cloudflare Workers, with built-in TypeScript support, automatic documentation generation, and interoperability with npm packages. It is indexed under Package Registries.

Source: https://jsr.io

Is JSR free to use?

JSR is open source, so it can be self-hosted and used at no licence cost. It is released under the MIT licence. Pricing changes often, so verify at source before relying on it.

Source: https://jsr.io

What platforms does JSR support?

JSR supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://jsr.io

Can JSR be self-hosted?

Yes. JSR can be deployed cloud / SaaS and self-hosted, so it does not have to run on the vendor's infrastructure.

Source: https://jsr.io

What does JSR integrate with?

We have confirmed 6 integrations for JSR, including Node.js, Deno, Bun, Cloudflare Workers, npm and Algolia. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://jsr.io

Is JSR open source?

Yes. JSR is published under the MIT licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.

Source: https://github.com/jsr-io/jsr

JSR alternatives

Other package registries we track, ranked by the same independent score.

All JSR alternatives, ranked →

Compare JSR

Side by side against other package registries, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for JSR, not the verdict.

Balanced composite 44 / 100
low · 43%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Development activity560.116.0
Security score540.084.4
Capabilities460.094.0
Stars660.031.8
Integrations240.051.3
Dependent projects00.070.0
Release cadence00.070.0-
Security posture00.180.0-
Package downloads00.150.0-
Developer Q&A activity00.050.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d57mediumsource · 2026-09-10 · 65%

Adoption

AttributeValueEvidence
Github stars2,973highsource · 2026-09-10 · 90%
Dependent repos0highsource · 2026-09-10 · 85%

Content

AttributeValueEvidence
Faq6 itemsmediumsource · 2026-09-10 · 66%

Features

AttributeValueEvidence
CapabilitiesRole: public_registry · Ecosystem: polyglot · Deployment: saas · Open source: oss · Pricing model: free · Package formats: singlemediumsource · 2026-09-10 · 60%

Integrations

AttributeValueEvidence
Count6mediumsource · 2026-08-14 · 60%

Language

AttributeValueEvidence
PrimaryRusthighsource · 2026-09-10 · 90%

License

AttributeValueEvidence
SpdxMIThighsource · 2026-09-10 · 95%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-08-14 · 75%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-09-10 · 60%
Modelopen_sourcemediumsource · 2026-09-10 · 60%
Price levelfreemediumsource · 2026-09-10 · 60%
TransparentYesmediumsource · 2026-08-14 · 60%

Security

AttributeValueEvidence
Scorecard5.4highsource · 2026-09-10 · 90%
VulnerabilitiesCount: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fjsr-io%2Fjsr&per_page=100 · Last 12m: 0highsource · 2026-09-10 · 90%
Still deciding?

Is JSR the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank JSR against the rest of the package registries we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of JSR

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves JSR up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows JSR's independent score and links back to this profile.

JSR, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/jsr" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/jsr.svg" alt="JSR, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![JSR, verified on vioscaleAI](https://www.vioscale.ai/badge/software/jsr.svg)](https://www.vioscale.ai/software/jsr)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing JSR. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim JSR

Not the owner? How vendor profiles work