</>PackageGraphPackageGraph

loofah

RubyGemsv2.25.2

Safe to adopt

Yes — loofah scores well across adoption, maintenance, weight, supply chain, and licensing. 185.6M downloads per week and 1 known dependents. Last published 56 days ago. 7 releases in the last 2 years.

  • AAdoption: grade A, Excellent.

    185.6M downloads per week and 1 known dependents.

  • AMaintenance: grade A, Excellent.

    Last published 56 days ago. 7 releases in the last 2 years.

  • AWeight: grade A, Excellent.

    Pulls in 4 transitive packages.

  • ASupply chain: grade A, Excellent.

    No install scripts, 2 maintainers, and a contained dependency surface.

  • ALicense: grade A, Excellent.

    MIT — permissive, with no copyleft found in the dependency tree.

Grades are computed deterministically from registry metadata collected by PackageGraph — downloads, dependents, publish dates, the resolved dependency tree, maintainer count, and declared licenses. No third-party scores are used.

Install cost

What you actually take on by adding loofah to a project.

2
Direct dependencies

Runtime packages this one declares itself.

4
Total installed

Distinct packages in the full runtime tree, deduplicated the way a package manager would.

Install size

Unpacked size of this package plus its entire runtime tree.

2
Tree depth

Longest resolved dependency chain below this package.

Licenses in the dependency tree

MITRuby

Every license you inherit by installing loofah, not just its own. Check this before a legal review, not after.

Compatibility

Ruby
No constraint declared

Dependencies

Declared by loofah v2.25.2. Runtime dependencies are installed with the package; dev dependencies are not.

Used by

Popular packages that depend on loofah.

Relationship graph

Dependencies (left) and dependents (right) of loofah.

crassnokogirirails-html-saniti…loofah
loofah dependencies dependents

Frequently installed together

Release history

5 releases in the last two years, typically about 68 days apart.

Recent versions of loofah
VersionPublishedSizeLicense
2.25.2latest1 month agoMIT
2.25.15 months agoMIT
2.25.08 months agoMIT
2.24.11 year agoMIT
2.24.01 year agoMIT
2.23.11 year agoMIT
2.23.01 year agoMIT
2.22.02 years agoMIT
2.21.42 years agoMIT
2.21.33 years agoMIT
2.21.23 years agoMIT
2.21.13 years agoMIT
2.21.03 years agoMIT
2.20.03 years agoMIT
2.19.13 years agoMIT

Overview

loofah is an RubyGems package. It is extremely widely used, with about 185.6M downloads per week and 1 known dependents in the graph. The latest version is 2.25.2, released under the MIT license.

Who should use it

Teams working in the RubyGems ecosystem who need this functionality and value a battle-tested, widely-adopted solution.

When not to use it

Consider an alternative if you need to or if a more actively-maintained option better fits your RubyGems stack.

Pros

  • Large, well-established user base (185.6M weekly downloads).
  • Clear open-source license (MIT).
  • Lean dependency tree (2 direct dependencies).

Cons

  • No significant drawbacks detected from available metadata.

Auto-generated from collected registry metadata. No external claims are inferred.

Maintainers

Frequently asked questions

Should I use loofah?

Yes — loofah scores well across adoption, maintenance, weight, supply chain, and licensing. 185.6M downloads per week and 1 known dependents. Last published 56 days ago. 7 releases in the last 2 years.

How do I install loofah?

Run `gem install loofah` to add loofah to your RubyGems project.

How many dependencies does loofah have?

loofah declares 2 direct dependencies and pulls in 4 packages in total once its runtime tree is resolved.

What license is loofah released under?

loofah is distributed under the MIT license. Its dependency tree also includes: MIT, Ruby.

How popular is loofah?

loofah has approximately 185,634,348 downloads per week and 1 known dependent packages.

Is loofah still maintained?

The most recent release of loofah (v2.25.2) was published 1 month ago.