About
Community
joinhoney.com
153 packages
Last scanned on Jan 19 at 08:22 AM
Update
Name
Size
Popularity
Severity
lodash
4.17.16
Vulnerable
Outdated
Lodash modular utilities.
Script
https://cdn.joinhoney.com/js/honey-website/34.18.2/vendors~7d359b94.bundle.js
License
MIT
Footprint
9 KB
Vulnerabilities
High
GHSA-35jh-r3h4-6jhm
Command Injection in lodash
Affected versions >=0 <4.17.21
Moderate
GHSA-29mw-wpgm-hmr9
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
High
GHSA-p6mc-m468-83gw
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
Also used on 4830 websites
skype.com
20 packages
sentry.io
157 packages
pinterest.com
56 packages
pinimg.com
52 packages
Repository
Homepage
More
modules
stdlib
util
moment
2.19.0 - 2.25.1
Vulnerable
Outdated
Parse, validate, manipulate, and display dates
moment
date
time
parse
format
+4
+2
d3-color
1.4.1 - 3.0.1
Vulnerable
Outdated
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
d3
d3-module
color
rgb
hsl
+4
es5-ext
0.10.24 - 0.10.49
Vulnerable
Outdated
ECMAScript extensions and shims
ecmascript
ecmascript5
ecmascript6
es5
es6
+11
medikoo
next
9.3.6 - 13.1.2
Vulnerable
Outdated
The React Framework
semver
7.3.8
Outdated
The semantic version parser used by npm.
+2
lru-cache
5.1.1 - 6.0.0
Outdated
A cache object that deletes the least-recently-used items.
mru
lru
cache
isaacs
yallist
3.0.3 - 4.0.0
Outdated
Yet Another Linked List
isaacs
readable-stream
3.6.0
Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
readable
stream
pipe
uuid
8.3.0 - 8.3.2
Outdated
RFC4122 (v1, v4, and v5) UUIDs
uuid
guid
rfc4122
string_decoder
1.1.0 - 1.3.0
The string_decoder module from Node core
string
decoder
browser
browserify
+1
isarray
1.0.0 - 2.0.5
Array#isArray for older browsers
browser
isarray
array
juliangruber
react-is
16.3.0 - 17.0.2
Outdated
Brand checking of React Elements.
react
+1
inherits
2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
inheritance
class
klass
oop
object-oriented
+3
isaacs
buffer
4.6.0 - 4.9.2
Outdated
Node.js Buffer API, for the browser
arraybuffer
browser
browserify
buffer
compatible
+2
feross
entities
2.2.0
Outdated
Encode & decode XML and HTML entities with ease & speed
entity
decoding
encoding
html
xml
+1
feedic
@babel/runtime
7.18.0 - 7.20.1
Outdated
babel's modular runtime helpers
+1
get-intrinsic
1.1.0 - 1.1.1
Outdated
Get and robustly cache all JS language-level intrinsics at first require time
javascript
ecmascript
es
js
intrinsic
+2
ljharb
function-bind
1.1.0 - 1.1.1
Outdated
Implementation of Function.prototype.bind
function
bind
shim
es5
cookie
0.2.4 - 0.4.2
Outdated
HTTP server cookie parsing and serialization
cookie
cookies
dougwilson
call-bind
1.0.2
Outdated
Robustly `.call.bind()` a function
javascript
ecmascript
es
js
callbind
+8
ljharb
core-util-is
1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
util
isBuffer
isArray
isNumber
isString
+4
isaacs
has-symbols
1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
Symbol
symbols
typeof
sham
polyfill
+3
ljharb
domutils
1.7.0
Outdated
Utilities for working with htmlparser2's dom
dom
htmlparser2
feedic
es-abstract
1.18.0 - 1.19.2
Outdated
ECMAScript spec abstract operations.
ECMAScript
ES
abstract
operation
abstract operation
+4
ljharb
base64-js
1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
base64
define-properties
1.1.3 - 1.1.4
Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
Object.defineProperty
Object.defineProperties
object
property descriptor
descriptor
+2
ljharb
dom-serializer
0.2.0 - 0.2.2
Outdated
render domhandler DOM nodes to a string
html
xml
render
feedic
is-callable
1.2.4
Outdated
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
Function
function
callable
generator
generator function
+5
ljharb
domhandler
2.4.0 - 2.4.2
Outdated
Handler for htmlparser2 that turns pages into a dom
dom
htmlparser2
feedic
has-tostringtag
1.0.0
Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
javascript
ecmascript
symbol
symbols
tostringtag
+1
ljharb
events
3.0.0 - 3.3.0
Node's event emitter for all engines.
events
eventEmitter
eventDispatcher
listeners
is-buffer
1.1.4 - 1.1.6
Outdated
Determine if an object is a Buffer
arraybuffer
browser
browser buffer
browserify
buffer
+10
feross
object-keys
1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
Object.keys
keys
ES5
shim
ljharb
regexp.prototype.flags
1.4.1
Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
RegExp.prototype.flags
regex
regular expression
ES6
shim
+6
ljharb
domelementtype
1.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
dom
element
types
htmlparser2
feedic
core-js
3.25.1 - 3.27.1
Outdated
Standard library
ES3
ES5
ES6
ES7
ES2015
+39
zloirock
is-regex
1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
regex
regexp
is
regular expression
regular
+1
ljharb
is-date-object
1.0.5
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
Date
ES6
toStringTag
@@toStringTag
Date object
ljharb
content-type
1.0.4
Outdated
Create and parse HTTP Content-Type header
content-type
http
req
res
rfc7231
dougwilson
es-to-primitive
1.2.0 - 1.2.1
ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.
primitive
abstract
ecmascript
es5
es6
+11
ljharb
htmlparser2
3.10.0 - 3.10.1
Outdated
Fast & forgiving HTML/XML parser
html
parser
streams
xml
dom
+3
feedic
extend
3.0.2
Port of jQuery.extend for node.js and the browser
extend
clone
merge
scheduler
0.21.0 - 0.23.0
Outdated
Cooperative scheduler for the browser environment.
react
+1
has
1.0.1 - 1.0.3
Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
prop-types
15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react
is-arguments
1.1.1
Is this an arguments object? It's a harder question than you think.
arguments
js
javascript
is-arguments
is
+1
ljharb
react
17.0.0 - 18.2.0
Outdated
React is a JavaScript library for building user interfaces.
react
+1
react-dom
18.2.0
Outdated
React package for working with the DOM.
react
+2
long
5.2.0 - 5.2.1
Outdated
A Long class for representing a 64-bit two's-complement integer value.
math
long
int64
dcode
lodash.debounce
4.0.8
The lodash method `_.debounce` exported as a module.
lodash-modularized
debounce
performance-now
0.1.3 - 2.1.0
Implements performance.now (based on process.hrtime).
meryn
deep-equal
1.1.0 - 1.1.1
Outdated
node's assert.deepEqual algorithm
equality
equal
compare
ljharb
url
0.11.0
Outdated
The core `url` packaged standalone for use with Browserify.
parsing
url
analyze
dayjs
1.11.6 - 1.11.7
Outdated
2KB immutable date time library alternative to Moment.js with the same modern API
dayjs
date
time
immutable
moment
iamkun
minimalistic-assert
1.0.0 - 1.0.1
minimalistic-assert ===
object-is
1.1.0 - 1.1.5
Outdated
ES2015-compliant shim for Object.is - differentiates between -0 and +0
is
Object.is
equality
sameValueZero
ES6
+4
ljharb
hoist-non-react-statics
3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
react
mridgway
classnames
2.3.2
Outdated
A simple utility for conditionally joining classNames together
react
css
classes
classname
classnames
+2
sha.js
2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
graphql
14.0.0 - 14.7.0
Outdated
A Query Language and Runtime which can target any service.
graphql
graphql-js
+5
react-transition-group
4.1.0 - 4.4.5
A react component toolset for managing animations
react
transition
addons
transition-group
animation
+2
dom-helpers
5.0.1 - 5.2.1
tiny modular DOM lib for ie9+
dom-helpers
react-component
dom
api
cross-browser
+8
validator
13.7.0
Outdated
String validation and sanitization
validator
validation
validate
sanitization
sanitize
+3
asn1.js
5.2.0 - 5.4.1
ASN.1 encoder and decoder
asn.1
der
hash-base
3.0.4 - 3.1.0
abstract base class for hash-streams
hash
stream
+1
elliptic
6.5.4
Outdated
EC cryptography
EC
Elliptic
curve
Cryptography
indutny
hash.js
1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
hash
sha256
sha224
hmac
indutny
react-router
6.4.3 - 6.7.0
Outdated
Declarative routing for React
react
router
route
routing
history
+1
hmac-drbg
1.0.1
Deterministic random bit generator (hmac)
hmac
drbg
prng
indutny
lodash-es
4.17.21
Lodash exported as ES modules.
es6
modules
stdlib
util
redux
4.1.0 - 4.2.0
Outdated
Predictable state container for JavaScript apps
redux
reducer
state
predictable
functional
+6
+3
react-router-dom
6.0.0 - 6.7.0
Outdated
Declarative routing for React web applications
react
router
route
routing
history
+1
react-fast-compare
3.1.0 - 3.2.0
Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
fast
equal
react
compare
shouldComponentUpdate
+1
+12
des.js
1.0.1
Outdated
DES implementation
DES
3DES
EDE
CBC
indutny
md5.js
1.1.0 - 1.3.5
node style md5 on pure JavaScript
crypto
md5
+2
pbkdf2
3.1.0 - 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
pbkdf2
kdf
salt
hash
+3
cipher-base
1.0.4
abstract base class for crypto-streams
cipher
stream
parse-asn1
5.1.6
Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
browserify-sign
2.4.0 - 2.8.0
Outdated
adds node crypto signing for browsers
+2
browserify-aes
0.4.0 - 0.8.1
Outdated
aes, for browserify
aes
crypto
browserify
+2
stream-http
2.8.2 - 2.8.3
Outdated
Streaming http in the browser
http
stream
streaming
xhr
http-browserify
evp_bytestokey
1.0.3
The insecure key derivation algorithm from OpenSSL
crypto
openssl
timers-browserify
2.0.9
Outdated
timers module for browserify
timers
browserify
browser
+36
browserify-rsa
4.1.0
RSA for browserify
+2
create-ecdh
3.0.0 - 4.0.4
createECDH but browserifiable
diffie
hellman
diffiehellman
ECDH
+2
d3-array
1.0.1 - 2.3.1
Outdated
Array manipulation, ordering, searching, summarizing, etc.
d3
d3-module
histogram
bisect
shuffle
+4
public-encrypt
4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
diffie-hellman
1.1.2
Outdated
pure js diffie-hellman
diffie
hellman
diffiehellman
dh
+2
browserify-des
1.0.2
browserify-des ===
miller-rabin
1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
prime
miller-rabin
bignumber
randomfill
1.0.0 - 1.0.4
random fill from browserify stand alone
crypto
random
querystring-es3
0.2.1
Node's querystring module for all engines. (ES3 compat fork)
commonjs
query
querystring
spaintrain
reselect
4.1.1 - 4.1.7
Outdated
Selectors for Redux.
react
redux
+3
d3-interpolate
1.4.0 - 3.0.1
Interpolate numbers, colors, strings, arrays, objects, whatever!
d3
d3-module
interpolate
interpolation
color
md5
2.2.1 - 2.3.0
js function for hashing messages with MD5
raf
3.0.0 - 3.1.0
Outdated
requestAnimationFrame polyfill for node and the browser
requestAnimationFrame
polyfill
crypt
0.0.0 - 0.0.2
utilities for encryption and hashing
pvorb
charenc
0.0.0 - 0.0.2
character encoding utilities
pvorb
d3-shape
1.1.1 - 1.3.7
Outdated
Graphical primitives for visualization, such as lines and areas.
d3
d3-module
graphics
visualization
canvas
+1
jwt-decode
3.0.0 - 3.1.2
Outdated
Decode JWT tokens, mostly useful for browser applications.
jwt
browser
+42
d3-path
1.0.3 - 3.0.1
Outdated
Serialize Canvas path commands to SVG.
d3
d3-module
canvas
path
svg
+4
idb
5.0.0 - 7.1.1
Outdated
A small wrapper that makes IndexedDB usable
jaffathecake
to-arraybuffer
1.0.1
Get an ArrayBuffer from a Buffer as fast as possible
buffer
to
arraybuffer
fast
read
+1
jhiesey
d3-format
1.4.0 - 3.1.0
Format numbers for human consumption.
d3
d3-module
format
localization
use-callback-ref
1.1.0
Outdated
The same useRef, but with callback
react
hook
useRef
createRef
merge refs
kashey
redux-thunk
2.1.0 - 2.4.2
Outdated
Thunk middleware for Redux.
redux
thunk
middleware
redux-middleware
flux
+2
lodash.throttle
4.1.1
The lodash method `_.throttle` exported as a module.
lodash-modularized
throttle
react-popper
2.2.5 - 2.3.0
Official library to use Popper on React projects
react
react-popper
popperjs
component
drop
+2
hyphenate-style-name
1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
hyphenate
style
css
camelcase
rexxars
@mui/system
5.0.0 - 5.11.5
Outdated
MUI System is a set of CSS utilities to help you build custom designs more efficiently. It makes it possible to rapidly lay out custom designs.
react
react-component
mui
system
+7
framer-motion
3.8.0 - 8.5.0
Outdated
A simple and powerful JavaScript animation library
react animation
react
three
3d
pose
+8
+36
react-i18next
8.0.5 - 9.0.10
Outdated
Internationalization for react done right. Using the i18next i18n ecosystem.
i18next
internationalization
i18n
translation
localization
+4
@firebase/component
0.5.8 - 0.6.0
Outdated
Firebase Component Platform
+1
@angular/core
2.0.0 - 2.4.10
Outdated
Angular - the core framework
@sentry/react
6.3.1 - 7.31.1
Outdated
Official Sentry SDK for React.js
+8
@firebase/logger
0.3.0 - 0.4.0
Outdated
A logger package for use in the Firebase JS SDK
+1
jss
10.0.0 - 10.9.2
Outdated
A lib for generating Style Sheets with JavaScript.
jss
style
sheet
stylesheet
css
+4
kof
react-datepicker
0.59.0
Outdated
A simple and reusable datepicker component for React
react
datepicker
calendar
date
react-component
fp-ts
2.6.6 - 2.10.5
Outdated
Functional programming in TypeScript
typescript
algebraic-data-types
functional-programming
gcanti
string-convert
0.2.0 - 0.2.1
String convertions
akiran
json2mq
0.2.0
Generate media query string from JSON or javascript object
akiran
css-vendor
2.0.7 - 2.0.8
CSS vendor prefix detection and property feature testing.
css
vendor
feature
test
prefix
+3
@datadog/browser-core
1.2.2 - 4.30.1
Outdated
Datadog browser core utilities.
datadog
react-side-effect
2.1.0 - 2.1.2
Create components whose prop changes map to a global side effect
react
component
side
effect
react-helmet
6.0.0 - 6.1.0
A document head manager for React
react-helmet
nfl
react
document
head
+7
+2
@firebase/app
0.7.18 - 0.9.0
Outdated
The primary entrypoint to the Firebase JS SDK
+1
react-intersection-observer
8.33.0 - 9.0.0
Outdated
Monitor if a component is inside the viewport, using IntersectionObserver API
react
component
hooks
viewport
intersection
+5
thebuilder
@headlessui/react
1.3.0 - 1.4.3
Outdated
A set of completely unstyled, fully accessible UI components for React, designed to integrate beautifully with Tailwind CSS.
+1
@firebase/firestore
0.1.0 - 0.3.7
Outdated
The Cloud Firestore component of the Firebase JS SDK.
+1
@firebase/remote-config
0.2.0 - 0.4.0
Outdated
The Remote Config package of the Firebase JS SDK
+1
universal-cookie
4.0.1 - 4.0.4
Outdated
Universal cookies for JavaScript
universal
isomophic
cookie
exon
d3-collection
1.0.1 - 1.0.7
Handy data structures for elements keyed by string.
d3
d3-module
nest
data
map
+3
rc-select
10.0.0 - 14.2.0
Outdated
React Select
react
react-component
react-select
select
+6
enquire.js
2.1.6
Awesome Media Queries in JavaScript
media query
media queries
matchMedia
enquire
enquire.js
wickynilliams
react-slick
0.29.0
Outdated
React port of slick carousel
slick
carousel
Image slider
orbit
slider
+1
akiran
@reach/utils
0.10.4 - 0.11.2
Outdated
Internal, shared utilities for Reach UI.
+1
react-cookie
3.0.0 - 4.1.1
Outdated
Universal cookies for React
universal
isomophic
cookie
react
exon
react-scroll
1.8.9
Outdated
A scroll component for React.js
react
react-component
scroll
scroller
scrolls
fisshy
@loadable/component
5.15.0 - 5.15.2
Outdated
React code splitting made easy.
react
ssr
webpack
code-splitting
react-router
+4
gatsby
1.9.197 - 1.9.201
Outdated
Blazing fast modern site generator for React
blog
generator
jekyll
markdown
react
+2
+10
accounting
0.4.1
number, money and currency formatting library
accounting
number
money
currency
format
+3
openexchangerates
react-html-parser
2.0.2
Parse HTML into React components
react
html
htmlparser
htmlparser2
inner html
+1
wrakky
react-jss
10.4.0 - 10.9.2
Outdated
JSS integration with React
react
style
css
stylesheet
jss
+2
theming
3.1.0 - 3.3.0
Unified CSSinJS theming solution for React
react
theme
theming
styled-components
jss
+2
css-jss
10.0.0 - 10.9.2
Outdated
Implements css() interface on top of JSS
jss
style
sheet
stylesheet
css
+4
kof
store
2.0.12
A localStorage wrapper for all browsers without using cookies or flash. Uses localStorage, globalStorage, and userData behavior under the hood
marcuswestin
blurhash
2.0.1
Outdated
Encoder and decoder for the Wolt BlurHash algorithm.
blurhash
blur
hash
image
+2
deepcopy
2.0.0 - 2.1.0
deep copy data
sasaplus1
@tannin/plural-forms
1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
lottie-api
1.0.0 - 1.0.2
Outdated
A library to edit lottie-web animations dynamically
airnan
tg-core-redux
0.0.5 - 0.0.8
Outdated
tg-core-redux
+4
@team-griffin/react-heading-section
0.0.1
Outdated
```sh npm i --save @team-griffin/react-heading-section
+1
Popular search queries
webpack.js.org
url
react-scripts
react
lottie-api
react-helmet-async
+7 packages
github.com
color-convert
@headlessui/react
hoist-non-react-statics
reactstrap
lit-html
+60 packages
pinterest.com
lodash
relay-runtime
react-relay
react-use
lodash-es
+51 packages
Popular packages
react
React is a JavaScript library for building user interfaces.
+6 634 websites
core-js
Standard library
+10 238 websites
es5-ext
ECMAScript extensions and shims
+10 229 websites
@babel/runtime
babel's modular runtime helpers
+8 352 websites
lodash
Lodash modular utilities.
+4 826 websites
axios
Promise based HTTP client for the browser and node.js
+4 742 websites