lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
14 KB
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
axios 0.21.0 - 0.21.1VulnerableOutdated
Promise based HTTP client for the browser and node.js
d3-color 1.4.1 - 3.0.1VulnerableOutdated
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
gsap 1.20.5 - 2.1.2VulnerableOutdated
GSAP is a framework-agnostic JavaScript animation library that turns developers into animation superheroes. Build high-performance animations that work in **every** major browser. Animate CSS, SVG, canvas, React, Vue, WebGL, colors, strings, motion paths,
markdown-it 2.0.0 - 3.1.0VulnerableOutdated
Markdown-it - modern pluggable markdown parser.
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
debug 2.3.1 - 3.1.0Outdated
Lightweight debugging utility for Node.js and the browser
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
inherits 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
entities 2.2.0Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.13.6 - 7.20.7Outdated
babel's modular runtime helpers
get-intrinsic 1.1.2 - 1.1.3Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
path-to-regexp 1.7.0 - 2.4.0Outdated
Express style path to RegExp utility
call-bind 1.0.1 - 1.0.2Outdated
Robustly `.call.bind()` a function
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
has-property-descriptors 1.0.0Outdated
Does the environment have full property descriptor support? Handles IE 8's broken defineProperty/gOPD.
domutils 1.7.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
define-properties 1.1.3 - 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
dom-serializer 0.2.0 - 0.2.2Outdated
render domhandler DOM nodes to a string
domhandler 2.2.1 - 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
has-tostringtag 1.0.0Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
regexp.prototype.flags 1.4.2 - 1.4.3Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
domelementtype 1.2.0 - 1.3.1Outdated
all the types of nodes in htmlparser2's dom
core-js 3.23.3 - 3.27.1Outdated
Standard library
htmlparser2 3.10.0 - 3.10.1Outdated
Fast & forgiving HTML/XML parser
functions-have-names 1.1.1 - 1.2.3
Does this JS environment support the `name` property on functions?
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
scheduler 0.15.0 - 0.23.0Outdated
Cooperative scheduler for the browser environment.
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 16.13.0 - 18.2.0Outdated
React is a JavaScript library for building user interfaces.
json-stringify-safe 5.0.1
Like JSON.stringify, but doesn't blow up on circular refs.
url 0.10.0 - 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
date-fns 1.30.1Outdated
Modern JavaScript date utility library
object-is 1.1.0 - 1.1.5Outdated
ES2015-compliant shim for Object.is - differentiates between -0 and +0
html-entities 2.0.4 - 2.3.3Outdated
Fastest HTML entities encode/decode library.
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
handlebars 4.0.0 - 4.7.7Outdated
Handlebars provides the power necessary to let you build semantic templates effectively with no frustration
path-browserify 0.0.0 - 0.0.1Outdated
the path module from node core for browsers
@emotion/unitless 0.7.2 - 0.8.0Outdated
An object of css properties that don't accept values with units
classnames 2.2.2 - 2.2.6Outdated
A simple utility for conditionally joining classNames together
@emotion/is-prop-valid 0.8.8Outdated
A function to check whether a prop is valid for HTML and SVG elements
react-transition-group 2.0.0 - 2.2.1Outdated
A react component toolset for managing animations
dom-helpers 5.0.1 - 5.2.1
tiny modular DOM lib for ie9+
webpack-merge 2.3.0Outdated
Variant of merge that's useful for webpack configuration
tiny-invariant 0.0.2 - 1.3.1Outdated
A tiny invariant function
memoize-one 5.2.0 - 5.2.1Outdated
A memoization library which only remembers the latest invocation
lodash-es 4.17.1 - 4.17.21
Lodash exported as ES modules.
d3-array 1.2.0 - 1.2.4Outdated
Array manipulation, ordering, searching, summarizing, etc.
character-entities-legacy 2.0.0Outdated
List of legacy HTML named character references that don’t need a trailing semicolon
querystring-es3 0.2.0 - 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
loglevel 0.3.1Outdated
Minimal lightweight logging for JavaScript, adding reliable log level methods to any available console.log methods
@xmldom/xmldom 0.7.0 - 0.8.6Outdated
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
history 4.0.0 - 4.10.1Outdated
Manage session history with JavaScript
d3-interpolate 1.4.0Outdated
Interpolate numbers, colors, strings, arrays, objects, whatever!
d3-time 1.1.0 - 3.0.0Outdated
A calculator for humanity’s peculiar conventions of time.
d3-shape 1.1.1 - 1.3.7Outdated
Graphical primitives for visualization, such as lines and areas.
d3-path 1.0.3 - 3.0.1Outdated
Serialize Canvas path commands to SVG.
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
d3-format 1.4.4 - 1.4.5Outdated
Format numbers for human consumption.
d3-scale 1.0.3 - 2.0.0Outdated
Encodings that map abstract data to visual representation.
d3-time-format 2.3.0Outdated
A JavaScript time formatter and parser inspired by strftime and strptime.
is-what 1.0.4 - 4.1.8Outdated
JS type check (TypeScript supported) functions like `isPlainObject() isArray()` etc. A simple & small integration.
styled-components 0.0.1 - 5.3.6Outdated
CSS for the <Component> Age. Style components your way with speed, strong typing, and flexibility.
libphonenumber-js 1.10.14Outdated
A simpler (and smaller) rewrite of Google Android's libphonenumber library in javascript
d3-timer 1.0.2 - 1.0.10Outdated
An efficient queue capable of managing thousands of concurrent animations.
react-popper 1.3.4 - 1.3.11Outdated
Official library to use Popper on React projects
@emotion/stylis 0.6.2 - 0.6.7Outdated
A custom build of Stylis
d3-ease 1.0.7 - 3.0.1
Easing functions for smooth animation.
popper.js 1.12.6 - 1.16.1
A kickass library to manage your poppers
resolve-pathname 3.0.0
Resolve URL pathnames using JavaScript
foreach 2.0.4 - 2.0.6
foreach component + npm package
jss 9.0.0 - 9.1.0Outdated
A lib for generating Style Sheets with JavaScript.
react-onclickoutside 6.2.0 - 6.12.2Outdated
An onClickOutside wrapper for React components
exenv 1.1.0 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
swiper 6.6.1 - 6.6.2Outdated
Most modern mobile touch slider and framework with hardware accelerated transitions
gud 1.0.0
Create a 'gud nuff' (not cryptographically secure) globally unique id
faker 1.0.0 - 2.1.5Outdated
Generate massive amounts of fake contextual data
react-side-effect 1.2.0 - 2.1.2
Create components whose prop changes map to a global side effect
mini-create-react-context 0.3.2Outdated
Smaller Polyfill for the proposed React context API
firebase 4.1.4 - 4.5.0Outdated
Firebase JavaScript library for web and Node.js
create-react-class 15.5.0 - 15.7.0
Legacy API for creating React components.
xstate 4.7.0 - 4.29.0Outdated
Finite State Machines and Statecharts for the Modern Web.
recharts 1.6.0 - 2.2.0Outdated
React charts
react-smooth 0.1.3 - 1.0.0Outdated
react animation library
react-modal 3.14.1 - 3.16.1
Accessible modal dialog component for React.JS
algoliasearch 3.35.1Outdated
A fully-featured and blazing-fast JavaScript API client to interact with Algolia API.
d3-collection 1.0.1 - 1.0.7
Handy data structures for elements keyed by string.
mobx 2.3.0 - 6.7.0Outdated
Simple, scalable state management.
load-script 1.0.0 - 2.0.0
Dynamic script loading for browser
react-bootstrap 0.30.2 - 0.33.1Outdated
Bootstrap 5 components built with React
material-colors 1.2.2 - 1.2.6
Colors of Google's Material Design made available to coders
react-color 2.18.1Outdated
A Collection of Color Pickers from Sketch, Photoshop, Chrome & more
ssr-window 3.0.0Outdated
Better handling for window object in SSR environment
reactcss 1.2.0 - 1.2.3
Bringing Classes to Inline Styles
mobx-react 4.3.1 - 5.4.4Outdated
React bindings for MobX. Create fully reactive components.
consolidated-events 1.0.0 - 1.1.1Outdated
Manage multiple event handlers using few event listeners
react-player 2.2.0 - 2.11.0Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
dom7 3.0.0Outdated
Minimalistic JavaScript library for DOM manipulation, with a jQuery-compatible API
react-phone-number-input 3.2.0 - 3.2.14Outdated
Telephone number input React component
input-format 0.2.5 - 0.2.8Outdated
Formatting user's text input on-the-fly
react-dates 14.1.0 - 15.0.0Outdated
A responsive and accessible date range picker component built with React
react-native-web 0.0.118 - 0.2.2Outdated
React Native for Web
react-waypoint 7.3.0 - 9.0.0Outdated
A React component to execute a function whenever you scroll to an element.
sister 3.0.1 - 3.0.2
Event manager.
react-ga 2.2.0Outdated
React Google Analytics Module
react-youtube 7.12.0 - 7.14.0Outdated
React.js powered YouTube player component
react-html-parser 2.0.2
Parse HTML into React components
react-move 5.0.0 - 6.5.0
Beautiful, data-driven animations for React.
nuka-carousel 4.8.4Outdated
Pure React Carousel
kapellmeister 2.0.2 - 3.0.1
Orchestration For Animated Transitions
cross-domain-utils 1.0.10 - 2.0.38
Javascript module template.
react-bootstrap-table-next 3.1.2 - 4.0.3
Next generation of react-bootstrap-table
@sitecore-jss/sitecore-jss 1.0.2 - 6.1.2Outdated
This module is provided as a part of Sitecore JavaScript Rendering SDK. It contains the core JSS APIs (layout service) and utilities.
react-id-swiper 2.0.0 - 4.0.0
ReactJs component for iDangerous Swiper
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
woothee 0.3.0 - 0.4.2Outdated
User-Agent string parser (js implementation)
vuex-simple 1.2.1 - 1.2.2Outdated
A simpler way to write your Vuex store in Typescript
tg-core-components 0.0.2 - 6.3.0Outdated
@team-griffin/react-matchmedia-connect 0.1.3
Higher order component for matchMedia