// the find
douglascrockford/JSON-js
JSON in JavaScript
The reference implementation of JSON parsing/stringifying for pre-ES5 JavaScript, written by Douglas Crockford. json2.js polyfills the global JSON object for ancient browsers (IE8 and earlier); cycle.js adds decycle/retrocycle helpers for encoding cyclic object graphs that JSON can't natively represent.
json2.js's eval-based parser is guarded by regex checks that reject anything that isn't valid JSON before eval touches it, which was a reasonable defense-in-depth approach for its era. cycle.js solves a real gap in the JSON spec - representing DAGs and cycles - using JSONPath references, and the technique is simple enough to read in one sitting. The whole thing is two small, dependency-free files, easy to vendor if you actually need cycle.js.
json2.js is dead weight for any project shipping today - every JS engine has had native JSON.parse/stringify for over a decade, and the eval-based parser is a needless attack surface if it ever does get invoked. No package on npm, no build, no tests, no CI - this is copy-paste-into-your-project software, not a dependency you install. Last commit is from 2023 but the content hasn't materially changed in years; cycle.js in particular has had no maintenance and no modern alternatives comparison (structured clone, flatted, etc. now cover this better).