oec.world 104 packages

Last scanned on Jan 19 at 08:10 AM
lodash-es 3.0.0 - 4.16.1VulnerableOutdated
Lodash exported as ES modules.
63 B
Prototype Pollution in lodash
Affected versions >=0 <4.17.14
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.11
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Matched Modules
Version distribution in production
3 519
1 221
xmldom 0.1.1 - 0.6.0Vulnerable
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
axios 0.21.1VulnerableOutdated
Promise based HTTP client for the browser and node.js
d3-color 1.4.1 - 3.0.1VulnerableOutdated
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
next 3.0.2 - 6.1.2VulnerableOutdated
The React Framework
html-parse-stringify2 2.0.1Vulnerable
Parses well-formed HTML (meaning all tags closed) into an AST and back. quickly.
tslib 1.2.0 - 2.4.1Outdated
Runtime library for TypeScript helper functions
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
json5 0.0.0Outdated
JSON for Humans
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
@babel/runtime 7.13.6 - 7.13.7Outdated
babel's modular runtime helpers
get-intrinsic 1.1.0 - 1.1.1Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
define-properties 1.1.3 - 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
regexp.prototype.flags 1.2.0 - 1.3.2Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
core-js 2.6.12Outdated
Standard library
is-regex 1.1.2Outdated
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
is-date-object 1.0.1 - 1.0.3Outdated
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
array-includes 3.0.0 - 3.1.6Outdated
An ES7/ES2016 spec-compliant `Array.prototype.includes` shim/polyfill/replacement that works as far down as ES3.
string.prototype.trim 1.1.0 - 1.2.7Outdated
ES5 spec-compliant shim for String.prototype.trim
scheduler 0.15.0 - 0.23.0Outdated
Cooperative scheduler for the browser environment.
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
prop-types 15.7.0 - 15.7.2Outdated
Runtime type checking for React props and similar objects.
is-arguments 1.1.0Outdated
Is this an arguments object? It's a harder question than you think.
object.fromentries 1.0.0 - 2.0.6Outdated
ES proposal-spec-compliant Object.fromEntries shim.
regenerate-unicode-properties 9.0.0Outdated
Regenerate sets for Unicode properties and values.
unicode-match-property-value-ecmascript 2.0.0Outdated
Match a Unicode property or property alias to its canonical property name per the algorithm used for RegExp Unicode property escapes in ECMAScript.
unicode-property-aliases-ecmascript 1.1.0 - 2.1.0
Unicode property alias mappings in JavaScript format for property names that are supported in ECMAScript RegExp property escapes.
unicode-match-property-ecmascript 1.0.0 - 2.0.0
Match a Unicode property or property alias to its canonical property name per the algorithm used for RegExp Unicode property escapes in ECMAScript.
unicode-canonical-property-names-ecmascript 1.0.2 - 2.0.0
The set of canonical Unicode property names supported in ECMAScript RegExp property escapes.
deep-equal 1.1.0 - 1.1.1Outdated
node's assert.deepEqual algorithm
yn 3.1.1Outdated
Parse yes/no like values
clsx 1.1.1 - 1.2.1Outdated
A tiny (239B) utility for constructing className strings conditionally.
object-is 1.1.0 - 1.1.5Outdated
ES2015-compliant shim for Object.is - differentiates between -0 and +0
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
query-string 6.5.0 - 7.1.3Outdated
Parse and stringify URL query strings
repeat-element 1.1.4
Create an array by repeating the given value n times.
graphql 15.4.0Outdated
A Query Language and Runtime which can target any service.
dom-helpers 5.0.1 - 5.2.1
tiny modular DOM lib for ie9+
core-js-pure 3.7.0 - 3.15.2Outdated
Standard library
object.getownpropertydescriptors 2.0.0 - 2.1.5Outdated
ES2017 spec-compliant shim for `Object.getOwnPropertyDescriptors` that works in ES5.
es5-ext 0.4.0 - 0.5.1Outdated
ECMAScript extensions and shims
redux 4.0.1 - 4.2.0Outdated
Predictable state container for JavaScript apps
sourcemap-codec 1.4.5 - 1.4.8
Encode/decode sourcemap mappings
timers-browserify 2.0.9Outdated
timers module for browserify
d3-array 2.7.0 - 2.12.1Outdated
Array manipulation, ordering, searching, summarizing, etc.
filter-obj 1.1.0Outdated
Filter object keys and values into a new object
highlight.js 10.7.0 - 10.7.3Outdated
Syntax highlighting with language autodetection.
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
@babel/runtime-corejs3 7.10.0 - 7.13.10Outdated
babel's modular runtime helpers with core-js@3 polyfilling
void-elements 2.0.1Outdated
Array of "void elements" defined by the HTML specification.
d3-interpolate 1.4.0 - 3.0.1
Interpolate numbers, colors, strings, arrays, objects, whatever!
url-join 4.0.1Outdated
Join urls and normalize as in path.join.
d3-time 2.0.0 - 3.0.0Outdated
A calculator for humanity’s peculiar conventions of time.
d3-shape 2.0.0 - 3.0.1Outdated
Graphical primitives for visualization, such as lines and areas.
d3-path 1.0.3 - 3.0.1Outdated
Serialize Canvas path commands to SVG.
split-on-first 1.0.0 - 1.1.0Outdated
Split a string on the first occurance of a given separator
d3-format 1.4.0 - 3.1.0
Format numbers for human consumption.
d3-scale 3.3.0 - 4.0.0Outdated
Encodings that map abstract data to visual representation.
d3-time-format 3.0.0 - 4.1.0
A JavaScript time formatter and parser inspired by strftime and strptime.
d3-timer 1.0.2 - 3.0.1
An efficient queue capable of managing thousands of concurrent animations.
lodash.throttle 4.1.1
The lodash method `_.throttle` exported as a module.
popper.js 1.12.6 - 1.16.1
A kickass library to manage your poppers
d3-dispatch 1.0.6 - 3.0.1
Register named callbacks and call them with arguments.
d3-selection 2.0.0Outdated
Data-driven DOM manipulation: select elements and join them to data.
d3-transition 1.2.0 - 3.0.1
Animated transitions for D3 selections.
@apollo/client 3.0.0 - 3.7.4Outdated
A fully-featured caching GraphQL client.
fault 1.0.1 - 1.0.4Outdated
Functional errors with formatted output
d3-zoom 1.8.0 - 3.0.0
Pan and zoom SVG, HTML or Canvas using mouse or touch input.
format 0.2.2
printf, sprintf, and vsprintf for JavaScript
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
@angular/common 5.0.0 - 5.0.5Outdated
Angular - commonly needed directives and services
lowlight 1.20.0Outdated
Virtual syntax highlighting for virtual DOMs and non-HTML things
exenv 1.1.0 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
fp-ts 0.2.1 - 0.2.9Outdated
Functional programming in TypeScript
array.prototype.find 2.0.0 - 2.2.1Outdated
Array.prototype.find ES6 polyfill.
gud 1.0.0
Create a 'gud nuff' (not cryptographically secure) globally unique id
react-dnd 0.1.2 - 0.9.8Outdated
Drag and Drop for React
rc-slider 6.0.0 - 9.7.5Outdated
Slider UI component for React
create-react-class 15.7.0
Legacy API for creating React components.
clipboard 2.0.8Outdated
Modern copy to clipboard. No Flash. Just 2kb
recharts 0.17.1 - 1.8.6Outdated
React charts
element-resize-detector 1.2.4
Resize event emitter for elements.
batch-processor 1.0.0
Batch processing in JS
popmotion 9.3.0 - 11.0.5
The animator's toolbox
d3-collection 1.0.1 - 1.0.7
Handy data structures for elements keyed by string.
load-script 1.0.0 - 2.0.0
Dynamic script loading for browser
redux-devtools-extension 2.0.0 - 2.13.9
Wrappers for Redux DevTools Extension.
@loadable/component 5.13.0 - 5.15.2Outdated
React code splitting made easy.
bootstrap-vue 1.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
react-ga 3.1.2 - 3.3.1
React Google Analytics Module
amplitude-js 5.2.0Outdated
Javascript library for Amplitude Analytics
deepcopy 2.0.0 - 2.1.0
deep copy data
@wordpress/i18n 1.1.0 - 3.0.1Outdated
WordPress internationalization (i18n) library.
html-attributes 1.1.0
List of HTML attributes as a map of camelCased names.
filter-invalid-dom-props 1.0.0Outdated
a function to filter props that are not valid dom props when spreading props in an HOC in react
react-universal-component 1.5.0 - 3.0.1Outdated
A higher order component for loading components with promises
botframework-webchat-component 4.14.1 - 4.15.6Outdated
React component of botframework-webchat
prebid.js 0.7.0 - 3.15.0Outdated
Header Bidding Management Library