About
Community
20min.ch
65 packages
Last scanned on Oct 27 at 06:23 PM
Update
Name
Size
Popularity
Severity
lodash
4.17.16
Vulnerable
Outdated
Lodash modular utilities.
Script
https://20min.ch/_next/static/chunks/pages/_app-e76270ee84ca4110.js
License
MIT
Footprint
3 KB
Vulnerabilities
High
GHSA-p6mc-m468-83gw
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
High
GHSA-35jh-r3h4-6jhm
Command Injection in lodash
Affected versions >=0 <4.17.21
Moderate
GHSA-29mw-wpgm-hmr9
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
Also used on 4830 websites
skype.com
20 packages
cloudflare.com
116 packages
sentry.io
157 packages
pinterest.com
55 packages
Repository
Homepage
More
modules
stdlib
util
next-auth
3.24.1 - 3.29.10
Vulnerable
Outdated
Authentication for Next.js
react
nodejs
oauth
jwt
oauth2
+5
next
12.1.0 - 12.1.5
Vulnerable
Outdated
The React Framework
react-is
16.3.0 - 18.2.0
Brand checking of React Elements.
react
+1
buffer
5.7.0 - 6.0.3
Node.js Buffer API, for the browser
arraybuffer
browser
browserify
buffer
compatible
+2
feross
@babel/runtime
7.14.6 - 7.16.3
Outdated
babel's modular runtime helpers
+1
function-bind
1.1.0 - 1.1.1
Outdated
Implementation of Function.prototype.bind
function
bind
shim
es5
get-intrinsic
1.1.3
Outdated
Get and robustly cache all JS language-level intrinsics at first require time
javascript
ecmascript
es
js
intrinsic
+2
ljharb
object-inspect
1.12.2
Outdated
string representations of objects in node and the browser
inspect
util.inspect
object
stringify
pretty
has-symbols
1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
Symbol
symbols
typeof
sham
polyfill
+3
ljharb
call-bind
1.0.2
Outdated
Robustly `.call.bind()` a function
javascript
ecmascript
es
js
callbind
+8
ljharb
define-properties
1.1.4
Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
Object.defineProperty
Object.defineProperties
object
property descriptor
descriptor
+2
ljharb
base64-js
1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
base64
es-abstract
1.20.4
Outdated
ECMAScript spec abstract operations.
ECMAScript
ES
abstract
operation
abstract operation
+4
ljharb
is-callable
1.2.7
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
Function
function
callable
generator
generator function
+5
ljharb
has-property-descriptors
1.0.0
Outdated
Does the environment have full property descriptor support? Handles IE 8's broken defineProperty/gOPD.
property
descriptors
has
environment
env
+2
ljharb
nanoid
3.1.30 - 3.3.4
Outdated
A tiny (116 bytes), secure URL-friendly unique string ID generator
uuid
random
id
url
ai
domhandler
4.2.0 - 5.0.3
Handler for htmlparser2 that turns pages into a dom
dom
htmlparser2
feedic
object-keys
1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
Object.keys
keys
ES5
shim
ljharb
domelementtype
2.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
dom
element
types
htmlparser2
feedic
is-regex
1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
regex
regexp
is
regular expression
regular
+1
ljharb
deepmerge
4.2.2
Outdated
A library for deep (recursive) merging of Javascript objects
merge
deep
extend
copy
clone
+1
tehshrike
has-tostringtag
1.0.0
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
javascript
ecmascript
symbol
symbols
tostringtag
+1
ljharb
has
1.0.1 - 1.0.3
Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
is-date-object
1.0.5
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
Date
ES6
toStringTag
@@toStringTag
Date object
ljharb
is-string
1.0.7
Is this value a JS String object or primitive? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
String
string
ES6
toStringTag
@@toStringTag
+1
ljharb
es-to-primitive
1.2.0 - 1.2.1
ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.
primitive
abstract
ecmascript
es5
es6
+11
ljharb
scheduler
0.21.0 - 0.23.0
Cooperative scheduler for the browser environment.
react
+1
array-includes
3.1.2 - 3.1.5
Outdated
An ES7/ES2016 spec-compliant `Array.prototype.includes` shim/polyfill/replacement that works as far down as ES3.
Array.prototype.includes
includes
array
ES7
shim
+4
ljharb
requires-port
1.0.0
Check if a protocol requires a certain port number to be added to an URL.
port
require
http
https
ws
+11
react
17.0.0 - 18.2.0
React is a JavaScript library for building user interfaces.
react
+1
react-dom
18.1.0
Outdated
React package for working with the DOM.
react
+2
dayjs
1.8.1 - 1.10.1
Outdated
2KB immutable date time library alternative to Moment.js with the same modern API
dayjs
date
time
immutable
moment
iamkun
string.prototype.trim
1.2.6
Outdated
ES5 spec-compliant shim for String.prototype.trim
String.prototype.trim
string
ES5
shim
trim
+2
ljharb
url-parse
1.5.9 - 1.5.10
Small footprint URL parser that works seamlessly across Node.js and browser environments
URL
parser
uri
url
parse
+4
+1
querystringify
2.2.0
Querystringify - Small, simple but powerful query string parser.
query
string
query-string
querystring
qs
+4
+1
object.entries
1.0.0 - 1.1.5
Outdated
ES2017 spec-compliant Object.entries shim.
Object.entries
Object.values
Object.keys
entries
values
+8
ljharb
hoist-non-react-statics
3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
react
mridgway
react-transition-group
4.1.0 - 4.4.5
A react component toolset for managing animations
react
transition
addons
transition-group
animation
+2
stackframe
1.2.0 - 1.3.4
JS Object representation of a stack frame
stacktrace
error
debugger
stack frame
+1
es5-ext
0.3.0 - 0.6.3
Outdated
ECMAScript extensions and shims
ecmascript
ecmascript5
ecmascript6
es5
es6
+11
medikoo
@sentry/utils
5.7.0 - 6.13.1
Outdated
Utilities for all Sentry JavaScript SDKs
+8
es-array-method-boxes-properly
1.0.0
Utility package to determine if an `Array.prototype` method properly boxes the callback's receiver and third argument.
ljharb
shallowequal
1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
shallowequal
shallow
equal
isequal
compare
+1
dashed
styled-components
4.0.0 - 5.3.6
Outdated
CSS for the <Component> Age. Style components your way with speed, strong typing, and flexibility.
react
css
css-in-js
styled-components
styling
+1
react-redux
5.0.3 - 7.2.9
Outdated
Official React bindings for Redux
react
reactjs
redux
+2
polished
3.0.0 - 3.4.4
Outdated
A lightweight toolset for writing styles in Javascript.
styled-components
polished
emotion
glamor
css-in-js
+9
style-to-object
0.2.3 - 0.3.0
Outdated
Converts inline style to object.
style-to-object
inline
style
parser
css
+2
remarkablemark
inline-style-parser
0.1.0 - 0.1.1
Outdated
An inline style parser.
inline-style-parser
inline-style
style
parser
css
remarkablemark
intl-messageformat
3.0.0
Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
i18n
intl
internationalization
localization
globalization
+4
+9
@reduxjs/toolkit
1.3.4 - 1.8.6
Outdated
The official, opinionated, batteries-included toolset for efficient Redux development
redux
react
starter
toolkit
reducer
+4
+2
focus-lock
0.8.0 - 0.11.3
Outdated
DOM trap for a focus
focus
trap
vanilla
kashey
react-dnd
15.0.0 - 16.0.1
Drag and Drop for React
+2
@material-ui/core
4.9.8 - 4.12.4
React components that implement Google's Material Design.
react
react-component
material design
material-ui
html-react-parser
1.4.5 - 3.0.4
Outdated
HTML to React parser.
html-react-parser
html
react
parser
dom
remarkablemark
react-property
2.0.0
Outdated
HTML and SVG DOM property configs used by React.
react-property
html
svg
dom
property
+4
remarkablemark
style-to-js
1.1.0
Outdated
Parses CSS inline style to JavaScript object (camelCased).
style-to-js
css
style
javascript
object
+1
remarkablemark
@chakra-ui/theme
2.1.0 - 2.1.3
Outdated
The default theme for chakra components
theme
theming
ui mode
ui
node-polyglot
2.4.1 - 2.4.2
Outdated
Give your JavaScript the ability to speak many languages.
i18n
internationalization
internationalisation
translation
interpolation
+2
+2
@tannin/plural-forms
1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
lottie-api
1.0.0 - 1.0.2
Outdated
A library to edit lottie-web animations dynamically
airnan
botframework-webchat-component
4.15.4
Outdated
React component of botframework-webchat
+2
prebid.js
2.10.0 - 3.11.0
Outdated
Header Bidding Management Library
advertising
auction
header bidding
prebid
+1
react-amphtml
3.1.0 - 4.0.2
Use amphtml components inside your React apps easily!
react
amphtml
dfrankland
js-component-framework
2.0.0 - 2.0.2
Outdated
A framework for configuring a JavaScript component and attaching it to a DOM element or collection of DOM elements, simplifying organization of DOM interactions on your website.
es6
Popular search queries
webpack.js.org
url
react-scripts
react
lottie-api
react-helmet-async
+7 packages
github.com
color-convert
engine.io-client
lit-html
intl-messageformat
web-vitals
+21 packages
pinterest.com
lodash
relay-runtime
react-query
react-relay
react-use
+50 packages
Popular packages
react
React is a JavaScript library for building user interfaces.
+6 634 websites
core-js
Standard library
+10 238 websites
es5-ext
ECMAScript extensions and shims
+10 229 websites
@babel/runtime
babel's modular runtime helpers
+8 352 websites
lodash
Lodash modular utilities.
+4 826 websites
axios
Promise based HTTP client for the browser and node.js
+4 742 websites