About
Community
kqed.org
159 packages
Last scanned on Oct 27 at 07:07 PM
Update
Name
Size
Popularity
Severity
moment
2.29.1
Vulnerable
Outdated
Parse, validate, manipulate, and display dates
License
MIT
Footprint
12 KB
Vulnerabilities
High
GHSA-wc69-rhjr-hc9g
Moment.js vulnerable to Inefficient Regular Expression Complexity
Affected versions >=2.18.0 <2.29.4
High
GHSA-8hfj-j24r-96c4
Path Traversal: 'dir/../../filename' in moment.locale
Affected versions >=0 <2.29.2
Matched Modules
Version distribution in production
241
2.25.1
240
2.19.0
240
2.25.0
127
2.29.1
112
2.29.3
90
2.29.4
Also used on 778 websites
sentry.io
157 packages
behance.net
30 packages
brightcove.com
94 packages
newyorker.com
29 packages
Repository
Homepage
More
moment
date
time
parse
format
+4
+2
decode-uri-component
0.2.0
Vulnerable
Outdated
A better decodeURIComponent
decode
uri
component
decodeuricomponent
components
+2
samverschueren
d3-color
1.4.1
Vulnerable
Outdated
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
d3
d3-module
color
rgb
hsl
+4
moment-timezone
0.5.34
Vulnerable
Outdated
Parse and display moments in any timezone.
moment
date
time
timezone
olson
+3
+4
@firebase/util
0.3.2
Vulnerable
Outdated
_NOTE: This is specifically tailored for Firebase JS SDK usage, if you are not a member of the Firebase team, please avoid using this package_
+1
striptags
3.1.0 - 3.1.1
Vulnerable
Outdated
PHP strip_tags in Node.js
striptags
strip_tags
html
strip
tags
ericnorris
tslib
1.13.0 - 1.14.1
Outdated
Runtime library for TypeScript helper functions
TypeScript
Microsoft
compiler
language
javascript
+2
+5
isarray
1.0.0 - 2.0.5
Array#isArray for older browsers
browser
isarray
array
juliangruber
react-is
16.13.1
Outdated
Brand checking of React Elements.
react
+1
buffer
4.9.2
Outdated
Node.js Buffer API, for the browser
arraybuffer
browser
browserify
buffer
compatible
+2
feross
regenerator-runtime
0.13.9
Outdated
Runtime for Regenerator-compiled generator and async functions.
regenerator
runtime
generator
async
benjamn
lodash
4.17.21
Lodash modular utilities.
modules
stdlib
util
@babel/runtime
7.13.9 - 7.16.3
Outdated
babel's modular runtime helpers
+1
path-to-regexp
1.8.0
Outdated
Express style path to RegExp utility
express
regexp
route
routing
+2
rxjs
6.0.0 - 6.6.7
Outdated
Reactive Extensions for modern JavaScript
Rx
RxJS
ReactiveX
ReactiveExtensions
Streams
+5
ieee754
1.2.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
IEEE 754
buffer
convert
floating point
ieee754
feross
object-assign
4.1.1
ES2015 `Object.assign()` ponyfill
object
assign
extend
properties
es2015
+7
core-js
3.19.3
Outdated
Standard library
ES3
ES5
ES6
ES7
ES2015
+39
zloirock
base64-js
1.5.1
Base64 encoding/decoding in pure JS
base64
prop-types
15.7.0 - 15.7.2
Outdated
Runtime type checking for React props and similar objects.
react
scheduler
0.18.0
Outdated
Cooperative scheduler for the browser environment.
react
+1
react
16.14.0
Outdated
React is a JavaScript library for building user interfaces.
react
+1
process
0.11.10
process information for node.js and browsers
process
lodash.debounce
4.0.8
The lodash method `_.debounce` exported as a module.
lodash-modularized
debounce
react-dom
16.12.0
Outdated
React package for working with the DOM.
react
+2
css-loader
0.28.1 - 1.0.1
Outdated
css loader module for webpack
webpack
css
loader
url
import
@emotion/memoize
0.6.6 - 0.7.4
Outdated
emotion's memoize utility
+1
hoist-non-react-statics
3.3.2
Copies non-react specific statics from a child component to a parent component
react
mridgway
style-loader
0.23.1
Outdated
style loader module for webpack
webpack
invariant
2.2.3 - 2.2.4
invariant
test
invariant
remove-trailing-separator
1.0.0
Outdated
Removes separators from the end of the string.
remove
strip
trailing
separator
darsain
react-transition-group
4.1.0 - 4.2.1
Outdated
A react component toolset for managing animations
react
transition
addons
transition-group
animation
+2
dom-helpers
3.4.0
Outdated
tiny modular DOM lib for ie9+
dom-helpers
react-component
dom
api
cross-browser
+8
query-string
5.1.1
Outdated
Parse and stringify URL query strings
browser
querystring
query
string
qs
+9
sindresorhus
classnames
2.3.0 - 2.3.1
Outdated
A simple utility for conditionally joining classNames together
react
css
classes
classname
classnames
+2
symbol-observable
1.1.0 - 1.2.0
Outdated
Symbol.observable ponyfill
symbol
observable
observables
ponyfill
polyfill
+1
lodash.get
4.4.2
The lodash method `_.get` exported as a module.
lodash-modularized
get
whatwg-fetch
3.6.2
Outdated
A window.fetch polyfill.
@emotion/is-prop-valid
0.8.8
Outdated
A function to check whether a prop is valid for HTML and SVG elements
+1
strict-uri-encode
1.1.0
Outdated
A stricter URI encode adhering to RFC 3986
component
encode
RFC3986
uri
kevva
es5-ext
0.10.24 - 0.10.49
Outdated
ECMAScript extensions and shims
ecmascript
ecmascript5
ecmascript6
es5
es6
+11
medikoo
react-router
5.2.1 - 5.3.1
Outdated
Declarative routing for React
react
router
route
routing
history
+1
react-router-dom
5.3.0 - 5.3.3
Outdated
Declarative routing for React web applications
react
router
route
routing
history
+1
react-fast-compare
2.0.4
Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
fast
equal
react
compare
shouldComponentUpdate
+1
+16
tiny-invariant
1.2.0
Outdated
A tiny invariant function
invariant
error
assert
asserts
alexreardon
redux
3.7.0 - 3.7.2
Outdated
Predictable state container for JavaScript apps
redux
reducer
state
predictable
functional
+6
+3
history
4.10.1
Outdated
Manage session history with JavaScript
history
location
mjackson
lodash-es
4.17.3 - 4.17.21
Lodash exported as ES modules.
es6
modules
stdlib
util
shallowequal
1.1.0
Like lodash isEqualWith but for shallow equal.
shallowequal
shallow
equal
isequal
compare
+1
dashed
proto-list
1.0.0 - 1.1.0
Outdated
A utility for managing a prototype chain
isaacs
d3-array
1.2.1 - 1.2.4
Outdated
Array manipulation, ordering, searching, summarizing, etc.
d3
d3-module
histogram
bisect
shuffle
+4
react-redux
7.2.6
Outdated
Official React bindings for Redux
react
reactjs
redux
+2
luxon
1.1.0 - 3.0.4
Outdated
Immutable date wrapper
date
immutable
icambron
idb
3.0.0 - 3.0.2
Outdated
A small wrapper that makes IndexedDB usable
jaffathecake
d3-interpolate
1.4.0
Outdated
Interpolate numbers, colors, strings, arrays, objects, whatever!
d3
d3-module
interpolate
interpolation
color
resolve-pathname
3.0.0
Resolve URL pathnames using JavaScript
mjackson
value-equal
1.0.1
Are these two JavaScript values equal?
mjackson
d3-time
1.1.0
Outdated
A calculator for humanity’s peculiar conventions of time.
d3
d3-module
time
interval
calendar
isomorphic-fetch
2.1.1 - 3.0.0
Isomorphic WHATWG Fetch API, for Node & Browserify
d3-shape
1.3.6 - 1.3.7
Outdated
Graphical primitives for visualization, such as lines and areas.
d3
d3-module
graphics
visualization
canvas
+1
d3-format
1.4.5
Outdated
Format numbers for human consumption.
d3
d3-module
format
localization
d3-path
1.0.8 - 1.0.9
Outdated
Serialize Canvas path commands to SVG.
d3
d3-module
canvas
path
svg
+4
d3-scale
1.0.7
Outdated
Encodings that map abstract data to visual representation.
d3
d3-module
scale
visualization
d3-time-format
2.3.0
Outdated
A JavaScript time formatter and parser inspired by strftime and strptime.
d3
d3-module
time
format
strftime
+1
next
12.2.0 - 13.0.0
Outdated
The React Framework
lodash.throttle
4.1.1
The lodash method `_.throttle` exported as a module.
lodash-modularized
throttle
redux-thunk
2.4.0 - 2.4.1
Outdated
Thunk middleware for Redux.
redux
thunk
middleware
redux-middleware
flux
+2
d3-timer
1.0.7 - 2.0.0
Outdated
An efficient queue capable of managing thousands of concurrent animations.
d3
d3-module
timer
transition
animation
+3
d3-ease
1.0.7
Outdated
Easing functions for smooth animation.
d3
d3-module
ease
easing
animation
+1
@vue/shared
3.0.0 - 3.2.41
Outdated
internal utils shared across @vue packages
vue
yyx990803
react-hook-form
6.15.8
Outdated
Performant, flexible and extensible forms library for React Hooks
react
hooks
form
forms
form-validation
+3
bluebill1049
mini-create-react-context
0.3.3 - 0.4.1
Smaller Polyfill for the proposed React context API
react
context
contextTypes
polyfill
ponyfill
stringepsilon
react-scripts
0.4.2
Outdated
Configuration and scripts for Create React App.
+1
rc-util
4.20.3 - 5.3.0
Outdated
Common Utils For React Component
react
util
+6
@firebase/component
0.1.19 - 0.1.21
Outdated
Firebase Component Platform
+1
tiny-emitter
2.1.0
A tiny (less than 1k) event emitter library
event
emitter
pubsub
tiny
events
+1
scottcorgan
@firebase/logger
0.2.6
Outdated
A logger package for use in the Firebase JS SDK
+1
framer-motion
1.11.1
Outdated
A simple and powerful JavaScript animation library
react animation
react
three
3d
pose
+8
+30
lodash.set
4.3.2
The lodash method `_.set` exported as a module.
lodash-modularized
set
consolidated-events
2.0.2
Manage multiple event handlers using few event listeners
events
performance
lencioni
fp-ts
2.4.0 - 2.6.2
Outdated
Functional programming in TypeScript
typescript
algebraic-data-types
functional-programming
gcanti
json2mq
0.2.0
Generate media query string from JSON or javascript object
akiran
string-convert
0.1.0 - 0.2.1
String convertions
akiran
framesync
4.1.0
Outdated
A frame-synced render loop for JavaScript
animation
raf
popmotion
lottie-web
5.8.1
Outdated
After Effects plugin for exporting animations to SVG + JavaScript or canvas + JavaScript
animation
canvas
svg
after effects
plugin
+1
airnan
create-react-class
15.7.0
Legacy API for creating React components.
react
react-day-picker
7.4.10
Outdated
Customizable Date Picker for React
@firebase/app
0.6.11
Outdated
The primary entrypoint to the Firebase JS SDK
+1
clipboard
1.7.1
Outdated
Modern copy to clipboard. No Flash. Just 2kb
clipboard
copy
cut
react-helmet-async
1.2.2 - 1.2.3
Outdated
Thread-safe Helmet for React 16+ and friends
wonderboymusic
select
1.1.2
Programmatically select the text of a HTML element
range
select
selecting
selection
+1
delegate
3.2.0
Lightweight event delegation
event
delegate
delegation
+1
good-listener
1.1.5 - 1.2.2
A more versatile way of adding & removing event listeners
event
listener
hey-listen
1.0.6 - 1.0.8
Warning and invariant dev-ex messaging.
warning
invariant
popmotion
react-waypoint
9.0.3
Outdated
A React component to execute a function whenever you scroll to an element.
react
component
react-component
scroll
onscroll
+1
+2
firebase
7.24.0
Outdated
Firebase JavaScript library for web and Node.js
authentication
database
Firebase
firebase
realtime
+3
+1
@firebase/firestore
1.18.0
Outdated
The Cloud Firestore component of the Firebase JS SDK.
+1
@firebase/auth
0.15.0
Outdated
The Firebase Authenticaton component of the Firebase JS SDK.
+1
@firebase/installations
0.4.17
Outdated
+1
@firebase/webchannel-wrapper
0.4.0
Outdated
A wrapper of the webchannel packages from closure-library for use outside of a closure compiled application
+1
style-value-types
3.1.9 - 3.2.0
Outdated
Parsers, transformers and tests for special value types, eg: %, hex codes etc.
css
svg
hex
rgba
hsla
popmotion
@firebase/remote-config
0.1.28
Outdated
The Remote Config package of the Firebase JS SDK
+1
popmotion
8.7.2 - 8.7.6
Outdated
The animator's toolbox
animation
ux
ui
popmotion
canvas animation
+11
popmotion
d3-collection
0.1.2 - 1.0.7
Handy data structures for elements keyed by string.
d3
d3-module
nest
data
map
+3
antd
3.26.14 - 4.4.1
Outdated
An enterprise-class UI design language and React components implementation
ant
component
components
design
framework
+4
+4
enquire.js
2.1.6
Awesome Media Queries in JavaScript
media query
media queries
matchMedia
enquire
enquire.js
wickynilliams
@fortawesome/fontawesome-free
6.2.0
Outdated
The iconic font, CSS, and SVG framework
font
awesome
fontawesome
icon
svg
+1
+4
react-slick
0.15.4
Outdated
React port of slick carousel
slick
carousel
Image slider
orbit
slider
+1
akiran
can-use-dom
0.1.0
Test if you can use dom in the current environment
isomorphic
akiran
react-hot-loader
4.13.0
Outdated
Tweak React components in real time.
react
javascript
webpack
hmr
livereload
+5
+3
body-scroll-lock
3.1.4 - 3.1.5
Outdated
Enables body scroll locking (for iOS Mobile and Tablet, Android, desktop Safari/Chrome/Firefox) without breaking scrolling of a target element (eg. modal/lightbox/flyouts/nav-menus)
body scroll
body scroll lock
react scroll lock
react scroll
scroll
+16
willmcpo
react-responsive
6.1.2
Outdated
Media queries in react for responsive design
css
react-component
viewport
react
mobile
+6
sweetalert2
8.11.5 - 11.4.18
Outdated
A beautiful, responsive, customizable and accessible (WAI-ARIA) replacement for JavaScript's popup boxes, supported fork of sweetalert
sweetalert
sweetalert2
alert
modal
popup
+4
react-async-script
1.2.0
A composition mixin for loading scripts asynchronously for React
react
asynchronous
script-loader
dozoisch
@loadable/component
5.15.2
Outdated
React code splitting made easy.
react
ssr
webpack
code-splitting
react-router
+4
reduce-reducers
0.4.3
Outdated
Reduce multiple reducers into a single reducer
reduce
reducers
redux
react-scroll
1.8.3 - 1.8.5
Outdated
A scroll component for React.js
react
react-component
scroll
scroller
scrolls
fisshy
react-ga
2.7.0
Outdated
React Google Analytics Module
React
GA
Google Analytics
Universal Analytics
react-visibility-sensor
5.1.1
Sensor component for React that notifies you when it goes in or out of the window viewport.
react
react-component
visibility
+1
redux-actions
2.6.5
Outdated
Flux Standard Action utlities for Redux
flux
redux
fsa
actions
gatsby
1.9.223 - 1.9.279
Outdated
Blazing fast modern site generator for React
blog
generator
jekyll
markdown
react
+2
+10
react-measure
2.1.0 - 2.1.3
Outdated
Compute measurements of React components.
react
component
measure
measurements
dimensions
+3
souporserious
keymirror
0.1.0 - 0.1.1
A simple utility for creating an object with values equal to its keys. Identical to react/lib/keyMirror
strml
react-router-hash-link
1.2.1 - 1.2.2
Outdated
Hash link scroll functionality for React Router v4/5
react
react-router
link
hash-link
scroll
rafgraph
store
2.0.12
A localStorage wrapper for all browsers without using cookies or flash. Uses localStorage, globalStorage, and userData behavior under the hood
marcuswestin
dialog-polyfill
0.4.10
Outdated
Polyfill for the dialog element
@popmotion/easing
1.0.2
Easing functions, modifiers and generators compatible with most animation libraries.
animation
ux
ui
popmotion
canvas animation
+5
popmotion
@popmotion/popcorn
0.4.2 - 0.4.4
Utility functions for animation and interactions.
animation
raf
popmotion
stylefire
7.0.3
Performant, simplified stylers for CSS, SVG, path and DOM scroll.
css
svg
svg
path
scroll
+1
popmotion
react-lines-ellipsis
0.14.1
Outdated
Simple multiline ellipsis component for React.JS
react
react-component
multiline
ellipsis
dotdotdot
+2
xiaody
pose-core
2.1.1
Factory for Pose animation state machines
animation
dom
declarative
popmotion
popmotion
popmotion-pose
3.4.10 - 3.4.11
A declarative animation library for HTML and SVG
animation
dom
declarative
popmotion
popmotion
react-pose
4.0.10
A declarative animation library for React
animation
dom
declarative
popmotion
react
+1
popmotion
tiny-slider
2.9.4
Vanilla javascript slider for all purposes, inspired by Owl Carousel.
ganlanyuan
@tannin/plural-forms
1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
react-bootstrap-sweetalert
2.0.0 - 4.4.1
Outdated
A variant of sweetalert for use with React and Bootstrap
react
bootstrap
alert
sweetalert
confirm
+1
djorg83
lottie-api
1.0.0 - 1.0.2
Outdated
A library to edit lottie-web animations dynamically
airnan
botframework-webchat-component
4.9.2 - 4.15.4
Outdated
React component of botframework-webchat
+2
@team-griffin/redux-modal-router
0.1.0 - 0.3.0
Outdated
```sh yarn add @team-griffin/redux-modal-router
+1
iframe-lightbox
x.x.x
react-redux-firebase
x.x.x
victory-core
x.x.x
react-router-server
x.x.x
@firebase/analytics
x.x.x
@firebase/database
x.x.x
@firebase/functions
x.x.x
@firebase/messaging
x.x.x
@firebase/performance
x.x.x
@firebase/storage
x.x.x
disqus-react
x.x.x
react-google-publisher-tag
x.x.x
material-design-lite
x.x.x
victory-pie
x.x.x
json-groupby
x.x.x
@aarnila/react-instagram-embed
x.x.x
firebaseui
x.x.x
lodash.has
x.x.x
react-firebaseui
x.x.x
react-vimeo-oembed
x.x.x
Popular search queries
webpack.js.org
url
react-scripts
react
lottie-api
react-helmet-async
+8 packages
github.com
color-convert
engine.io-client
lit-html
intl-messageformat
web-vitals
+19 packages
pinterest.com
lodash
relay-runtime
react-query
react-relay
react-use
+50 packages
Popular packages
react
React is a JavaScript library for building user interfaces.
+6 634 websites
core-js
Standard library
+10 238 websites
es5-ext
ECMAScript extensions and shims
+10 229 websites
@babel/runtime
babel's modular runtime helpers
+8 352 websites
lodash
Lodash modular utilities.
+4 826 websites
axios
Promise based HTTP client for the browser and node.js
+4 742 websites