locals.com 79 packages

Last scanned on Jan 19 at 10:47 AM
url-parse 1.4.5 - 1.4.7VulnerableOutdated
Small footprint URL parser that works seamlessly across Node.js and browser environments
License
MIT
Footprint
3 KB
Vulnerabilities
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Affected versions >=0 <1.5.9
Authorization bypass in url-parse
Affected versions >=0 <1.5.6
Path traversal in url-parse
Affected versions >=0 <1.5.0
Open redirect in url-parse
Affected versions >=0 <1.5.2
Authorization Bypass Through User-Controlled Key in url-parse
Affected versions >=0 <1.5.8
url-parse Incorrectly parses URLs that include an '@'
Affected versions >=0 <1.5.7
Matched Modules
Version distribution in production
206
1.5.10
167
1.5.9
50
1.5.3
47
1.4.6
47
1.4.7
24
1.5.4
postcss 8.4.19VulnerableOutdated
Tool for transforming styles with JS plugins
markdown-it 12.0.4VulnerableOutdated
Markdown-it - modern pluggable markdown parser.
sanitize-html 2.7.1 - 2.8.0VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
debug 2.3.1 - 3.1.0Outdated
Lightweight debugging utility for Node.js and the browser
ms 2.0.0Outdated
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
escape-string-regexp 4.0.0 - 5.0.0
Escape RegExp special characters
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
entities 2.2.0Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.12.13 - 7.13.7Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
axios 0.21.4Outdated
Promise based HTTP client for the browser and node.js
is-plain-object 4.1.0 - 5.0.0
Returns true if an object was created by the `Object` constructor, or Object.create(null).
domutils 2.8.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
dom-serializer 1.0.0 - 1.4.1Outdated
render domhandler DOM nodes to a string
domhandler 4.2.2 - 4.3.1Outdated
Handler for htmlparser2 that turns pages into a dom
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
domelementtype 2.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
core-js 2.6.11Outdated
Standard library
htmlparser2 6.1.0Outdated
Fast & forgiving HTML/XML parser
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
querystringify 2.2.0
Querystringify - Small, simple but powerful query string parser.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
pretty-bytes 1.0.1 - 3.0.1Outdated
Convert bytes to a human readable string: 1337 → 1.34 kB
classnames 2.3.2Outdated
A simple utility for conditionally joining classNames together
memoize-one 5.2.0 - 5.2.1Outdated
A memoization library which only remembers the latest invocation
wildcard 1.1.1 - 1.1.2Outdated
Wildcard matching tools
damonoehlman
damonoehlman
moment-timezone 0.5.29 - 0.5.40Outdated
Parse and display moments in any timezone.
timers-browserify 2.0.9Outdated
timers module for browserify
mdurl 1.0.0 - 1.0.1Outdated
URL utilities for markdown-it
vitaly
vitaly
micromark 2.0.0 - 2.8.0Outdated
small commonmark compliant markdown parser with positional info and concrete tokens
linkify-it 3.0.2Outdated
Links recognition library with FULL unicode support
@xmldom/xmldom 0.7.0 - 0.8.6Outdated
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
uc.micro 1.0.6Outdated
Micro subset of unicode data files for markdown-it projects.
vitaly
vitaly
unfetch 4.1.0 - 4.2.0Outdated
Bare minimum fetch polyfill in 500 bytes
lodash.throttle 4.1.1
The lodash method `_.throttle` exported as a module.
js-base64 2.6.4Outdated
Yet another Base64 transcoder in pure-JS
dankogai
dankogai
popper.js 1.12.6 - 1.16.1
A kickass library to manage your poppers
engine.io-client 6.1.1Outdated
Client for the realtime Engine
rauchg
darrachequesne
is-function 1.0.2
is that thing a function? Use this module to find out
preact 10.4.8 - 10.11.3Outdated
Fast 3kb React-compatible Virtual DOM library.
vue-router 3.2.0 - 3.5.4Outdated
> - This is the repository for Vue Router 4 (for Vue 3) > - For Vue Router 3 (for Vue 2) see [vuejs/vue-router](https://github.com/vuejs/vue-router).
yyx990803
posva
swiper 6.6.0 - 6.6.1Outdated
Most modern mobile touch slider and framework with hardware accelerated transitions
parse-srcset 1.0.0 - 1.0.2
A spec-conformant JavaScript parser for the HTML5 srcset attribute
albell
albell
lit-element 3.0.1 - 3.2.2Outdated
A simple base class for creating fast, lightweight web components
+11
aomarks
emarquez
sorvell
react-query 0.0.11 - 0.0.15Outdated
Hooks for managing, caching and syncing asynchronous and remote data in React
tannerlinsley
tkdodo
load-script 1.0.0 - 2.0.0
Dynamic script loading for browser
ssr-window 3.0.0Outdated
Better handling for window object in SSR environment
nolimits4web
nolimits4web
safe-json-parse 2.0.0 - 4.0.0
Parse JSON safely without throwing
raynos
raynos
linkifyjs 2.1.4 - 2.1.9Outdated
Find URLs, email addresses, #hashtags and @mentions in plain-text strings, then convert them into HTML <a> links.
keycode 2.1.2 - 2.2.1
Convert between keyboard keycodes and keynames and vice versa.
mapbox-gl 0.19.0 - 0.26.0Outdated
A WebGL interactive maps library
+25
mbx-npm-ci-production
mbx-npm-ci-staging
mbx-npm-advanced-actions-production
dom7 3.0.0Outdated
Minimalistic JavaScript library for DOM manipulation, with a jQuery-compatible API
body-scroll-lock 2.7.0 - 3.1.5Outdated
Enables body scroll locking (for iOS Mobile and Tablet, Android, desktop Safari/Chrome/Firefox) without breaking scrolling of a target element (eg. modal/lightbox/flyouts/nav-menus)
@auth0/auth0-spa-js 2.0.0 - 2.0.2Outdated
Auth0 SDK for Single Page Applications using Authorization Code Grant Flow with PKCE
@videojs/vhs-utils 3.0.2 - 4.0.0
Objects and functions shared throughtout @videojs/http-streaming code
@soda/get-current-script 1.0.1 - 1.0.2
get the current executing script, with polyfills for IE9+ and Firefox
soda
soda
mux.js 6.0.0 - 6.2.0Outdated
A collection of lightweight utilities for inspecting and manipulating video container formats.
video.js 7.20.0 - 7.21.1Outdated
An HTML5 video player that supports HLS and DASH with a common API and skin.
scrollparent 0.1.0 - 2.0.1Outdated
A function to get the scrolling parent of an html element.
url-toolkit 2.2.4 - 2.2.5
Build an absolute URL from a base URL and a relative URL (RFC 1808). No dependencies!
m3u8-parser 4.6.0 - 4.8.0Outdated
m3u8 parser
mpd-parser 0.20.0 - 0.22.1Outdated
mpd parser
videojs-vtt.js 0.12.4 - 0.14.1Outdated
A JavaScript implementation of the WebVTT specification, forked from vtt.js for use with Video.js
sister 3.0.1 - 3.0.2
Event manager.
gajus
gajus
bootstrap-vue 1.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
vue-no-ssr 1.1.1
Vue component to wrap non SSR friendly components
egoist
rem
vue-client-only 2.0.0 - 2.1.0
Vue component to wrap non SSR friendly components
egoist
egoist
store 2.0.12
A localStorage wrapper for all browsers without using cookies or flash. Uses localStorage, globalStorage, and userData behavior under the hood
marcuswestin
marcuswestin
vuelidate 0.7.3 - 0.7.6Outdated
Simple, lightweight model-based validation for Vue.js
monterail-services
shentao
analytics-utils 0.0.7 - 0.0.11Outdated
Analytics utility functions used by 'analytics' module
v-tooltip 2.0.2 - 2.1.1Outdated
Easy tooltips with Vue 2.x
vue-lazyload 1.3.0 - 1.3.3Outdated
Vue module for lazy-loading images in your vue.js applications.
get-video-id 3.1.4Outdated
Get the YouTube, Vimeo, Vine, VideoPress, TikTok, Microsoft Stream, Loom or Dailymotion video id from a url or embed string.
mobile-device-detect 0.3.3Outdated
Helpers for handling mobile devices
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan