91 packages

Last scanned on Jan 19 at 07:55 AM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
4 KB
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
axios 0.17.1 - 0.18.0VulnerableOutdated
Promise based HTTP client for the browser and node.js
moment-timezone 0.5.25VulnerableOutdated
Parse and display moments in any timezone.
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
string_decoder 1.0.1 - 1.3.0
The string_decoder module from Node core
isarray 0.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
inherits 2.0.3 - 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
entities 2.2.0Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.18.2 - 7.20.1Outdated
babel's modular runtime helpers
path-to-regexp 3.0.0 - 3.2.0Outdated
Express style path to RegExp utility
isobject 3.0.0 - 4.0.0
Returns true if the value is an object and not an array or null.
rxjs 6.3.3 - 6.5.2Outdated
Reactive Extensions for modern JavaScript
is-plain-object 2.0.0 - 3.0.0Outdated
Returns true if an object was created by the `Object` constructor, or Object.create(null).
object-assign 1.0.0 - 3.0.0Outdated
ES2015 `Object.assign()` ponyfill
domutils 1.7.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
dom-serializer 0.2.0 - 0.2.2Outdated
render domhandler DOM nodes to a string
domhandler 2.4.0 - 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
is-buffer 1.1.4 - 1.1.6Outdated
Determine if an object is a Buffer
deepmerge 1.0.0 - 1.2.0Outdated
A library for deep (recursive) merging of Javascript objects
domelementtype 1.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
core-js 2.6.12Outdated
Standard library
util 0.10.0 - 0.12.5
Node.js's util module for all engines
htmlparser2 3.10.0 - 3.10.1Outdated
Fast & forgiving HTML/XML parser
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
scheduler 0.11.0 - 0.13.6Outdated
Cooperative scheduler for the browser environment.
prop-types 15.7.0 - 15.7.2Outdated
Runtime type checking for React props and similar objects.
url-parse 1.5.9 - 1.5.10
Small footprint URL parser that works seamlessly across Node.js and browser environments
make-error 1.3.1 - 1.3.6
Make your own error types!
querystringify 2.1.0 - 2.2.0
Querystringify - Small, simple but powerful query string parser.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
performance-now 0.1.3 - 2.1.0
Implements (based on process.hrtime).
hoist-non-react-statics 3.3.0 - 3.3.2
Copies non-react specific statics from a child component to a parent component
path-browserify 0.0.0 - 0.0.1Outdated
the path module from node core for browsers
assert 1.0.0 - 1.5.0Outdated
The assert module from Node.js, for the browser.
query-string 6.5.0 - 7.1.3Outdated
Parse and stringify URL query strings
tiny-invariant 0.0.2 - 1.3.1Outdated
A tiny invariant function
memoize-one 5.2.0 - 5.2.1Outdated
A memoization library which only remembers the latest invocation
lodash-es 4.17.21
Lodash exported as ES modules.
redux 4.0.1Outdated
Predictable state container for JavaScript apps
react-fast-compare 2.0.4 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
pluralize 5.1.0 - 8.0.0
Pluralize and singularize any word
babel-runtime 6.18.0 - 6.26.0
babel selfContained runtime
shallowequal 1.0.0 - 1.1.0
Like lodash isEqualWith but for shallow equal.
history 4.6.3 - 4.10.1Outdated
Manage session history with JavaScript
raf 3.0.0 - 3.1.0Outdated
requestAnimationFrame polyfill for node and the browser
d3-color 1.0.1 - 3.1.0
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
split-on-first 1.0.0 - 2.0.0Outdated
Split a string on the first occurance of a given separator
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
copy-to-clipboard 3.3.2 - 3.3.3
Copy stuff into clipboard using JS with fallbacks
redux-thunk 2.1.0 - 2.4.2Outdated
Thunk middleware for Redux.
toggle-selection 1.0.5 - 1.0.6
Toggle current selected content in browser
@aws-sdk/util-uri-escape 3.55.0 - 3.186.0Outdated
[![NPM version](]( [![NPM downloads](](
@reduxjs/toolkit 1.8.0 - 1.9.1Outdated
The official, opinionated, batteries-included toolset for efficient Redux development
@apollo/client 3.0.0 - 3.7.4Outdated
A fully-featured caching GraphQL client.
@hookform/resolvers 1.1.0Outdated
React Hook Form validation resolvers: Yup, Joi, Superstruct, Zod, Vest, Class Validator, io-ts, Nope, computed-types, TypeBox, arktype and Typanion
string-convert 0.2.0 - 0.2.1
String convertions
parse-headers 2.0.3 - 2.0.5
Parse http headers, works with browserify/xhr
react-side-effect 1.2.0Outdated
Create components whose prop changes map to a global side effect
gud 1.0.0
Create a 'gud nuff' (not cryptographically secure) globally unique id
react-helmet 5.0.0 - 5.2.1Outdated
A document head manager for React
lit-element 3.0.0Outdated
A simple base class for creating fast, lightweight web components
create-react-class 15.7.0
Legacy API for creating React components.
element-resize-detector 1.2.1 - 1.2.4
Resize event emitter for elements.
batch-processor 1.0.0
Batch processing in JS
react-day-picker 7.0.0 - 7.4.10Outdated
Customizable Date Picker for React
load-script 1.0.0 - 2.0.0
Dynamic script loading for browser
enquire.js 2.1.6
Awesome Media Queries in JavaScript
react-slick 0.23.0 - 0.23.2Outdated
React port of slick carousel
recompose 0.17.0 - 0.30.0
A React utility belt for function components and higher-order components
redux-devtools-extension 2.0.0 - 2.13.9
Wrappers for Redux DevTools Extension.
react-player 2.10.0 - 2.11.0Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
change-emitter 0.1.2 - 0.1.6
Listen for changes. Like an event emitter that only emits a single event type. Really tiny.
react-share 1.0.0 - 3.0.1Outdated
Social media share buttons and share counts for React.
react-autosuggest 10.0.1 - 10.1.0
WAI-ARIA compliant React autosuggest component
bootstrap-vue 1.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
react-html-parser 2.0.2
Parse HTML into React components
amplitude-js 5.2.0Outdated
Javascript library for Amplitude Analytics
react-router-hash-link 1.2.0 - 1.2.2Outdated
Hash link scroll functionality for React Router v4/5
@sanity/image-url 0.140.15 - 1.0.2
Tools to generate image urls from Sanity content
analytics 0.0.2Outdated
Lightweight analytics library for tracking events, page views, & identifying users. Works with any third party analytics provider via an extendable plugin system.
@sanity/generate-help-url 0.0.1 - 3.0.0
Generates URLs to specific sections of the Sanity documentation
vue-resource 0.5.0 - 0.6.0Outdated
The HTTP client for Vue.js
@sanity/block-content-to-hyperscript 3.0.0
Function for transforming Sanity block content to HyperScript
react-id-swiper 2.0.0 - 4.0.0
ReactJs component for iDangerous Swiper
react-headroom 2.2.7 - 3.1.1Outdated
Hide your header until you need it. React.js port of headroom.js
react-redux-loading-bar 4.0.0 - 5.0.4Outdated
Simple Loading Bar for Redux and React
web-speech-cognitive-services 5.0.0 - 7.1.0Outdated
Polyfill Web Speech API with Cognitive Services Speech-to-Text service
react-dictate-button 2.0.0 - 2.0.1
A button to start dictation using Web Speech API, with an easy to understand event lifecycle.