About
Community
kqed.org
159 packages
Last scanned on Oct 27 at 07:07 PM
Update
Name
Size
Popularity
Severity
moment
2.29.1
Vulnerable
Outdated
Parse, validate, manipulate, and display dates
License
MIT
Footprint
12 KB
Vulnerabilities
High
GHSA-wc69-rhjr-hc9g
Moment.js vulnerable to Inefficient Regular Expression Complexity
Affected versions >=2.18.0 <2.29.4
High
GHSA-8hfj-j24r-96c4
Path Traversal: 'dir/../../filename' in moment.locale
Affected versions >=0 <2.29.2
Matched Modules
Version distribution in production
241
2.25.1
240
2.19.0
240
2.25.0
127
2.29.1
112
2.29.3
90
2.29.4
Also used on 778 websites
sentry.io
157 packages
behance.net
30 packages
brightcove.com
94 packages
newyorker.com
29 packages
Repository
Homepage
More
moment
date
time
parse
format
+4
+2
d3-color
1.4.1
Vulnerable
Outdated
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
d3
d3-module
color
rgb
hsl
+4
moment-timezone
0.5.34
Vulnerable
Outdated
Parse and display moments in any timezone.
moment
date
time
timezone
olson
+3
+4
@firebase/util
0.3.2
Vulnerable
Outdated
_NOTE: This is specifically tailored for Firebase JS SDK usage, if you are not a member of the Firebase team, please avoid using this package_
+1
striptags
3.1.0 - 3.1.1
Vulnerable
Outdated
PHP strip_tags in Node.js
striptags
strip_tags
html
strip
tags
ericnorris
decode-uri-component
0.2.0
Vulnerable
Outdated
A better decodeURIComponent
decode
uri
component
decodeuricomponent
components
+2
samverschueren
tslib
1.13.0 - 1.14.1
Outdated
Runtime library for TypeScript helper functions
TypeScript
Microsoft
compiler
language
javascript
+2
+5
isarray
1.0.0 - 2.0.5
Array#isArray for older browsers
browser
isarray
array
juliangruber
react-is
16.13.1
Outdated
Brand checking of React Elements.
react
+3
@babel/runtime
7.13.9 - 7.16.3
Outdated
babel's modular runtime helpers
+1
buffer
4.9.2
Outdated
Node.js Buffer API, for the browser
arraybuffer
browser
browserify
buffer
compatible
+2
feross
lodash
4.17.21
Lodash modular utilities.
modules
stdlib
util
rxjs
6.0.0 - 6.6.7
Outdated
Reactive Extensions for modern JavaScript
Rx
RxJS
ReactiveX
ReactiveExtensions
Streams
+5
regenerator-runtime
0.13.9
Outdated
Runtime for Regenerator-compiled generator and async functions.
regenerator
runtime
generator
async
benjamn
path-to-regexp
1.8.0
Outdated
Express style path to RegExp utility
express
regexp
route
routing
+2
core-js
3.19.3
Outdated
Standard library
ES3
ES5
ES6
ES7
ES2015
+39
zloirock
ieee754
1.2.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
IEEE 754
buffer
convert
floating point
ieee754
feross
object-assign
4.1.1
ES2015 `Object.assign()` ponyfill
object
assign
extend
properties
es2015
+7
base64-js
1.5.1
Base64 encoding/decoding in pure JS
base64
css-loader
0.28.1 - 1.0.1
Outdated
css loader module for webpack
webpack
css
loader
url
import
prop-types
15.7.0 - 15.7.2
Outdated
Runtime type checking for React props and similar objects.
react
+2
scheduler
0.18.0
Outdated
Cooperative scheduler for the browser environment.
react
+3
react
16.14.0
Outdated
React is a JavaScript library for building user interfaces.
react
+3
lodash.debounce
4.0.8
The lodash method `_.debounce` exported as a module.
lodash-modularized
debounce
react-dom
16.12.0
Outdated
React package for working with the DOM.
react
+4
style-loader
0.23.1
Outdated
style loader module for webpack
webpack
process
0.11.10
process information for node.js and browsers
process
remove-trailing-separator
1.0.0
Outdated
Removes separators from the end of the string.
remove
strip
trailing
separator
darsain
hoist-non-react-statics
3.3.2
Copies non-react specific statics from a child component to a parent component
react
mridgway
query-string
5.1.1
Outdated
Parse and stringify URL query strings
browser
querystring
query
string
qs
+9
sindresorhus
@emotion/memoize
0.6.6 - 0.7.4
Outdated
emotion's memoize utility
+1
invariant
2.2.3 - 2.2.4
invariant
test
invariant
symbol-observable
1.1.0 - 1.2.0
Outdated
Symbol.observable ponyfill
symbol
observable
observables
ponyfill
polyfill
+1
strict-uri-encode
1.1.0
Outdated
A stricter URI encode adhering to RFC 3986
component
encode
RFC3986
uri
kevva
whatwg-fetch
3.6.2
A window.fetch polyfill.
react-transition-group
4.1.0 - 4.2.1
Outdated
A react component toolset for managing animations
react
transition
addons
transition-group
animation
+2
dom-helpers
3.4.0
Outdated
tiny modular DOM lib for ie9+
dom-helpers
react-component
dom
api
cross-browser
+8
classnames
2.3.0 - 2.3.1
Outdated
A simple utility for conditionally joining classNames together
react
css
classes
classname
classnames
+2
lodash.get
4.4.2
The lodash method `_.get` exported as a module.
lodash-modularized
get
@emotion/is-prop-valid
0.8.8
Outdated
A function to check whether a prop is valid for HTML and SVG elements
+1
es5-ext
0.10.24 - 0.10.49
Outdated
ECMAScript extensions and shims
ecmascript
ecmascript5
ecmascript6
es5
es6
+11
medikoo
react-router
5.2.1 - 5.3.1
Outdated
Declarative routing for React
react
router
route
routing
history
+1
history
4.10.1
Outdated
Manage session history with JavaScript
history
location
mjackson
react-router-dom
5.3.0 - 5.3.3
Outdated
Declarative routing for React web applications
react
router
route
routing
history
+1
redux
3.7.0 - 3.7.2
Outdated
Predictable state container for JavaScript apps
redux
reducer
state
predictable
functional
+6
+1
react-fast-compare
2.0.4
Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
fast
equal
react
compare
shouldComponentUpdate
+1
+17
shallowequal
1.1.0
Like lodash isEqualWith but for shallow equal.
shallowequal
shallow
equal
isequal
compare
+1
dashed
lodash-es
4.17.3 - 4.17.21
Lodash exported as ES modules.
es6
modules
stdlib
util
tiny-invariant
1.2.0
Outdated
A tiny invariant function
invariant
error
assert
asserts
alexreardon
proto-list
1.0.0 - 1.1.0
Outdated
A utility for managing a prototype chain
isaacs
react-redux
7.2.6
Outdated
Official React bindings for Redux
react
reactjs
redux
d3-array
1.2.1 - 1.2.4
Outdated
Array manipulation, ordering, searching, summarizing, etc.
d3
d3-module
histogram
bisect
shuffle
+4
isomorphic-fetch
2.1.1 - 3.0.0
Isomorphic WHATWG Fetch API, for Node & Browserify
d3-interpolate
1.4.0
Outdated
Interpolate numbers, colors, strings, arrays, objects, whatever!
d3
d3-module
interpolate
interpolation
color
resolve-pathname
3.0.0
Resolve URL pathnames using JavaScript
mjackson
value-equal
1.0.1
Are these two JavaScript values equal?
mjackson
d3-time
1.1.0
Outdated
A calculator for humanity’s peculiar conventions of time.
d3
d3-module
time
interval
calendar
luxon
1.1.0 - 3.0.4
Outdated
Immutable date wrapper
date
immutable
icambron
d3-format
1.4.5
Outdated
Format numbers for human consumption.
d3
d3-module
format
localization
d3-scale
1.0.7
Outdated
Encodings that map abstract data to visual representation.
d3
d3-module
scale
visualization
d3-shape
1.3.6 - 1.3.7
Outdated
Graphical primitives for visualization, such as lines and areas.
d3
d3-module
graphics
visualization
canvas
+1
d3-time-format
2.3.0
Outdated
A JavaScript time formatter and parser inspired by strftime and strptime.
d3
d3-module
time
format
strftime
+1
idb
3.0.0 - 3.0.2
Outdated
A small wrapper that makes IndexedDB usable
jaffathecake
d3-path
1.0.8 - 1.0.9
Outdated
Serialize Canvas path commands to SVG.
d3
d3-module
canvas
path
svg
+4
redux-thunk
2.4.0 - 2.4.1
Outdated
Thunk middleware for Redux.
redux
thunk
middleware
redux-middleware
flux
lodash.throttle
4.1.1
The lodash method `_.throttle` exported as a module.
lodash-modularized
throttle
next
12.2.0 - 13.0.0
Outdated
The React Framework
mini-create-react-context
0.3.3 - 0.4.1
Smaller Polyfill for the proposed React context API
react
context
contextTypes
polyfill
ponyfill
stringepsilon
d3-timer
1.0.7 - 2.0.0
Outdated
An efficient queue capable of managing thousands of concurrent animations.
d3
d3-module
timer
transition
animation
+3
react-scripts
0.4.2
Outdated
Configuration and scripts for Create React App.
+2
d3-ease
1.0.7
Outdated
Easing functions for smooth animation.
d3
d3-module
ease
easing
animation
+1
lodash.set
4.3.2
The lodash method `_.set` exported as a module.
lodash-modularized
set
tiny-emitter
2.1.0
A tiny (less than 1k) event emitter library
event
emitter
pubsub
tiny
events
+1
scottcorgan
rc-util
4.20.3 - 5.3.0
Outdated
Common Utils For React Component
react
util
+6
react-hook-form
6.15.8
Outdated
Performant, flexible and extensible forms library for React Hooks
react
hooks
form
forms
form-validation
+3
bluebill1049
@firebase/component
0.1.19 - 0.1.21
Outdated
Firebase Component Platform
+1
@vue/shared
3.0.0 - 3.2.41
Outdated
internal utils shared across @vue packages
vue
yyx990803
@firebase/logger
0.2.6
Outdated
A logger package for use in the Firebase JS SDK
+1
react-helmet-async
1.2.2 - 1.2.3
Outdated
Thread-safe Helmet for React 16+ and friends
wonderboymusic
create-react-class
15.7.0
Legacy API for creating React components.
react
+1
clipboard
1.7.1
Outdated
Modern copy to clipboard. No Flash. Just 2kb
clipboard
copy
cut
framesync
4.1.0
Outdated
A frame-synced render loop for JavaScript
animation
raf
popmotion
select
1.1.2
Programmatically select the text of a HTML element
range
select
selecting
selection
+1
good-listener
1.1.5 - 1.2.2
A more versatile way of adding & removing event listeners
event
listener
delegate
3.2.0
Lightweight event delegation
event
delegate
delegation
+1
framer-motion
1.11.1
Outdated
A simple and powerful React animation library
react animation
react
three
3d
pose
+7
+32
json2mq
0.2.0
Generate media query string from JSON or javascript object
akiran
string-convert
0.1.0 - 0.2.1
String convertions
akiran
hey-listen
1.0.6 - 1.0.8
Warning and invariant dev-ex messaging.
warning
invariant
popmotion
d3-collection
0.1.2 - 1.0.7
Handy data structures for elements keyed by string.
d3
d3-module
nest
data
map
+3
style-value-types
3.1.9 - 3.2.0
Outdated
Parsers, transformers and tests for special value types, eg: %, hex codes etc.
css
svg
hex
rgba
hsla
popmotion
popmotion
8.7.2 - 8.7.6
Outdated
The animator's toolbox
animation
ux
ui
popmotion
canvas animation
+11
popmotion
fp-ts
2.4.0 - 2.6.2
Outdated
Functional programming in TypeScript
typescript
algebraic-data-types
functional-programming
gcanti
@firebase/app
0.6.11
Outdated
The primary entrypoint to the Firebase JS SDK
+1
firebase
7.24.0
Outdated
Firebase JavaScript library for web and Node.js
authentication
database
Firebase
firebase
realtime
+3
+1
lottie-web
5.8.1
Outdated
After Effects plugin for exporting animations to SVG + JavaScript or canvas + JavaScript
animation
canvas
svg
after effects
plugin
+1
airnan
@firebase/installations
0.4.17
Outdated
+1
@firebase/firestore
1.18.0
Outdated
The Cloud Firestore component of the Firebase JS SDK.
+1
@firebase/auth
0.15.0
Outdated
The Firebase Authenticaton component of the Firebase JS SDK.
+1
consolidated-events
2.0.2
Manage multiple event handlers using few event listeners
events
performance
lencioni
@firebase/remote-config
0.1.28
Outdated
The Remote Config package of the Firebase JS SDK
+1
@firebase/webchannel-wrapper
0.4.0
Outdated
A wrapper of the webchannel packages from closure-library for use outside of a closure compiled application
+1
antd
3.26.14 - 4.4.1
Outdated
An enterprise-class UI design language and React components implementation
ant
component
components
design
framework
+4
+4
enquire.js
2.1.6
Awesome Media Queries in JavaScript
media query
media queries
matchMedia
enquire
enquire.js
wickynilliams
can-use-dom
0.1.0
Test if you can use dom in the current environment
isomorphic
akiran
react-hot-loader
4.13.0
Outdated
Tweak React components in real time.
react
javascript
webpack
hmr
livereload
+5
+3
react-slick
0.15.4
Outdated
React port of slick carousel
slick
carousel
Image slider
orbit
slider
+1
akiran
@fortawesome/fontawesome-free
6.2.0
Outdated
The iconic font, CSS, and SVG framework
font
awesome
fontawesome
icon
svg
+1
+4
react-waypoint
9.0.3
Outdated
A React component to execute a function whenever you scroll to an element.
react
component
react-component
scroll
onscroll
+1
+2
body-scroll-lock
3.1.4 - 3.1.5
Outdated
Enables body scroll locking (for iOS Mobile and Tablet, Android, desktop Safari/Chrome/Firefox) without breaking scrolling of a target element (eg. modal/lightbox/flyouts/nav-menus)
body scroll
body scroll lock
react scroll lock
react scroll
scroll
+16
willmcpo
react-day-picker
7.4.10
Outdated
Customizable Date Picker for React
react-responsive
6.1.2
Outdated
Media queries in react for responsive design
css
react-component
viewport
react
mobile
+6
react-async-script
1.2.0
A composition mixin for loading scripts asynchronously for React
react
asynchronous
script-loader
dozoisch
sweetalert2
8.11.5 - 11.4.18
Outdated
A beautiful, responsive, customizable and accessible (WAI-ARIA) replacement for JavaScript's popup boxes, supported fork of sweetalert
sweetalert
sweetalert2
alert
modal
popup
+4
@loadable/component
5.15.2
Outdated
React code splitting made easy.
react
ssr
webpack
code-splitting
react-router
+4
react-ga
2.7.0
Outdated
React Google Analytics Module
React
GA
Google Analytics
Universal Analytics
react-scroll
1.8.3 - 1.8.5
Outdated
A scroll component for React.js
react
react-component
scroll
scroller
scrolls
fisshy
gatsby
1.9.223 - 1.9.279
Outdated
Blazing fast modern site generator for React
blog
generator
jekyll
markdown
react
+2
+13
reduce-reducers
0.4.3
Outdated
Reduce multiple reducers into a single reducer
reduce
reducers
redux
react-measure
2.1.0 - 2.1.3
Outdated
Compute measurements of React components.
react
component
measure
measurements
dimensions
+3
souporserious
redux-actions
2.6.5
Flux Standard Action utlities for Redux
flux
redux
fsa
actions
react-visibility-sensor
5.1.1
Sensor component for React that notifies you when it goes in or out of the window viewport.
react
react-component
visibility
+1
keymirror
0.1.0 - 0.1.1
A simple utility for creating an object with values equal to its keys. Identical to react/lib/keyMirror
strml
store
2.0.12
A localStorage wrapper for all browsers without using cookies or flash. Uses localStorage, globalStorage, and userData behavior under the hood
marcuswestin
react-router-hash-link
1.2.1 - 1.2.2
Outdated
Hash link scroll functionality for React Router v4/5
react
react-router
link
hash-link
scroll
rafgraph
@popmotion/easing
1.0.2
Easing functions, modifiers and generators compatible with most animation libraries.
animation
ux
ui
popmotion
canvas animation
+5
popmotion
dialog-polyfill
0.4.10
Outdated
Polyfill for the dialog element
@popmotion/popcorn
0.4.2 - 0.4.4
Utility functions for animation and interactions.
animation
raf
popmotion
stylefire
7.0.3
Performant, simplified stylers for CSS, SVG, path and DOM scroll.
css
svg
svg
path
scroll
+1
popmotion
react-lines-ellipsis
0.14.1
Outdated
Simple multiline ellipsis component for React.JS
react
react-component
multiline
ellipsis
dotdotdot
+2
xiaody
tiny-slider
2.9.4
Vanilla javascript slider for all purposes, inspired by Owl Carousel.
ganlanyuan
pose-core
2.1.1
Factory for Pose animation state machines
animation
dom
declarative
popmotion
popmotion
popmotion-pose
3.4.10 - 3.4.11
A declarative animation library for HTML and SVG
animation
dom
declarative
popmotion
popmotion
react-pose
4.0.10
A declarative animation library for React
animation
dom
declarative
popmotion
react
+1
popmotion
@tannin/plural-forms
1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
react-bootstrap-sweetalert
2.0.0 - 4.4.1
Outdated
A variant of sweetalert for use with React and Bootstrap
react
bootstrap
alert
sweetalert
confirm
+1
djorg83
lottie-api
1.0.0 - 1.0.2
Outdated
A library to edit lottie-web animations dynamically
airnan
botframework-webchat-component
4.9.2 - 4.15.4
Outdated
React component of botframework-webchat
+2
@team-griffin/redux-modal-router
0.1.0 - 0.3.0
Outdated
```sh yarn add @team-griffin/redux-modal-router
+1
iframe-lightbox
x.x.x
react-redux-firebase
x.x.x
victory-core
x.x.x
react-router-server
x.x.x
@firebase/analytics
x.x.x
@firebase/database
x.x.x
@firebase/functions
x.x.x
@firebase/messaging
x.x.x
@firebase/performance
x.x.x
@firebase/storage
x.x.x
disqus-react
x.x.x
react-google-publisher-tag
x.x.x
material-design-lite
x.x.x
victory-pie
x.x.x
json-groupby
x.x.x
@aarnila/react-instagram-embed
x.x.x
firebaseui
x.x.x
lodash.has
x.x.x
react-firebaseui
x.x.x
react-vimeo-oembed
x.x.x
Popular search queries
webpack.js.org
url
react-scripts
react
lottie-api
react-helmet-async
+8 packages
github.com
engine.io-client
superagent
yup
ramda-adjunct
smoothscroll-polyfill
+13 packages
pinterest.com
lodash
relay-runtime
react-relay
react-use
lodash-es
+47 packages
Popular packages
react
React is a JavaScript library for building user interfaces.
+6 634 websites
core-js
Standard library
+10 238 websites
es5-ext
ECMAScript extensions and shims
+10 229 websites
@babel/runtime
babel's modular runtime helpers
+8 352 websites
lodash
Lodash modular utilities.
+4 826 websites
axios
Promise based HTTP client for the browser and node.js
+4 742 websites