crypto-js on a CDN

Copy the tag for crypto-js 4.2.0. Each provider below carries the url, the flavour it serves and the date it was last fetched.

How this one loads

crypto-js loads from an ordinary script tag and exposes a global, so nothing else is needed to use it on a page.

What is checked, and when

3 of 3 urls for crypto-js responded at the last check on 2026-09-05. Every one of them is listed with the answer it gave rather than assumed to be fine.

Licence and source

crypto-js is published under MIT, and its source is at http://github.com/brix/crypto-js. JavaScript library of crypto standards.

Questions

Are these URLs actually checked?

Yes, and that is the whole point of this site. Every url here was requested and the answer recorded — 276 of 290 responded successfully at the last check on 2026-09-05. A url we could not verify is labelled unverified rather than presented as working, and a url that failed says so along with how long it has been failing.

What is an SRI hash and do I need one?

Subresource integrity pins the exact bytes a browser will accept. If the file at that url ever changes, the browser refuses to run it instead of running something you did not review. Use one for anything on a page that handles user data. Only cdnjs publishes hashes, and only for the exact file they computed it from — attaching a hash to a different url blocks the script and looks exactly like the CDN being down.