About
Community
soompi.com
116 packages
Last scanned on Oct 27 at 06:46 PM
Update
Name
Size
Popularity
Severity
lodash-es
3.10.0 - 3.10.1
Vulnerable
Outdated
Lodash exported as ES modules.
License
MIT
Vulnerabilities
Critical
GHSA-jf85-cpcp-j695
Prototype Pollution in lodash
Affected versions >=0 <4.17.14
Moderate
GHSA-x5rq-j2xg-h7qm
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.11
High
GHSA-35jh-r3h4-6jhm
Command Injection in lodash
Affected versions >=0 <4.17.21
Moderate
GHSA-29mw-wpgm-hmr9
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
High
GHSA-p6mc-m468-83gw
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.20
Version distribution in production
3 519
4.17.21
1 221
4.17.20
526
4.10.0
420
4.17.11
419
4.17.15
181
3.10.1
Also used on 4452 websites
skype.com
20 packages
snapchat.com
69 packages
sentry.io
157 packages
pinterest.com
56 packages
Repository
Homepage
More
es6
modules
stdlib
util
lodash
4.17.9 - 4.17.19
Vulnerable
Outdated
Lodash modular utilities.
modules
stdlib
util
axios
0.18.1
Vulnerable
Outdated
Promise based HTTP client for the browser and node.js
xhr
http
ajax
promise
node
+1
lazysizes
5.0.0
Vulnerable
Outdated
High performance (jankfree) lazy loader for images (including responsive images), iframes and scripts (widgets).
lazy
loader
lazyloader
lazyload
lazySizes
+16
@firebase/util
0.2.2 - 0.2.6
Vulnerable
Outdated
_NOTE: This is specifically tailored for Firebase JS SDK usage, if you are not a member of the Firebase team, please avoid using this package_
+1
es5-ext
0.10.24 - 0.10.49
Vulnerable
Outdated
ECMAScript extensions and shims
ecmascript
ecmascript5
ecmascript6
es5
es6
+11
medikoo
tslib
1.9.0
Outdated
Runtime library for TypeScript helper functions
TypeScript
Microsoft
compiler
language
javascript
+2
+5
isarray
0.0.0 - 0.0.1
Outdated
Array#isArray for older browsers
browser
isarray
array
juliangruber
react-is
16.8.6
Outdated
Brand checking of React Elements.
react
+1
regenerator-runtime
0.10.5
Outdated
Runtime for Regenerator-compiled generator and async functions.
regenerator
runtime
generator
async
benjamn
@babel/runtime
7.4.0 - 7.12.18
Outdated
babel's modular runtime helpers
+1
function-bind
1.1.1
Outdated
Implementation of Function.prototype.bind
function
bind
shim
es5
path-to-regexp
1.7.0
Outdated
Express style path to RegExp utility
express
regexp
route
routing
+2
cookie
0.3.1
Outdated
HTTP server cookie parsing and serialization
cookie
cookies
dougwilson
has-symbols
1.0.0
Outdated
Determine if the JS environment has Symbol support. Supports spec, or shams.
Symbol
symbols
typeof
sham
polyfill
+3
ljharb
object-assign
4.1.1
ES2015 `Object.assign()` ponyfill
object
assign
extend
properties
es2015
+7
es-abstract
1.13.0
Outdated
ECMAScript spec abstract operations.
ECMAScript
ES
abstract
operation
abstract operation
+4
ljharb
define-properties
1.1.3
Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
Object.defineProperty
Object.defineProperties
object
property descriptor
descriptor
+2
ljharb
is-callable
1.1.4 - 1.1.5
Outdated
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
Function
function
callable
generator
generator function
+5
ljharb
events
3.0.0
Outdated
Node's event emitter for all engines.
events
eventEmitter
eventDispatcher
listeners
is-buffer
2.0.0 - 2.0.5
Determine if an object is a Buffer
arraybuffer
browser
browser buffer
browserify
buffer
+10
feross
object-keys
1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
Object.keys
keys
ES5
shim
ljharb
core-js
2.6.9
Outdated
Standard library
ES3
ES5
ES6
ES7
ES2015
+39
zloirock
is-regex
1.0.4
Outdated
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
regex
regexp
is
regular expression
regular
+1
ljharb
is-date-object
1.0.1
Outdated
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
Date
ES6
toStringTag
@@toStringTag
Date object
ljharb
is-symbol
1.0.2 - 1.0.4
Determine if a value is an ES6 Symbol or not.
symbol
es6
is
Symbol
ljharb
es-to-primitive
1.2.0
Outdated
ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.
primitive
abstract
ecmascript
es5
es6
+11
ljharb
object.values
1.0.4 - 1.1.0
Outdated
ES2017 spec-compliant Object.values shim.
Object.values
Object.keys
Object.entries
values
ES7
+8
ljharb
has
1.0.2 - 1.0.3
Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
scheduler
0.18.0
Outdated
Cooperative scheduler for the browser environment.
react
+1
prop-types
15.6.2
Outdated
Runtime type checking for React props and similar objects.
react
react
16.12.0
Outdated
React is a JavaScript library for building user interfaces.
react
+1
process
0.11.10
process information for node.js and browsers
process
react-dom
16.12.0
Outdated
React package for working with the DOM.
react
+2
setimmediate
1.0.5
A shim for the setImmediate efficient script yielding API
domenic
@emotion/memoize
0.6.6 - 0.7.4
Outdated
emotion's memoize utility
+1
html-entities
1.2.1
Outdated
Fastest HTML entities encode/decode library.
html
html entities
html entities encode
html entities decode
entities
+2
mdevils
hoist-non-react-statics
2.5.1 - 2.5.5
Outdated
Copies non-react specific statics from a child component to a parent component
react
mridgway
invariant
2.2.3 - 2.2.4
invariant
test
invariant
@emotion/unitless
0.7.2 - 0.7.5
Outdated
An object of css properties that don't accept values with units
+1
classnames
2.2.6
Outdated
A simple utility for conditionally joining classNames together
react
css
classes
classname
classnames
+2
stylis
3.5.4
Outdated
A Light–weight CSS Preprocessor
@emotion/is-prop-valid
0.8.1 - 0.8.3
Outdated
A function to check whether a prop is valid for HTML and SVG elements
+1
react-transition-group
2.9.0
Outdated
A react component toolset for managing animations
react
transition
addons
transition-group
animation
+2
dom-helpers
3.4.0
Outdated
tiny modular DOM lib for ie9+
dom-helpers
react-component
dom
api
cross-browser
+8
whatwg-fetch
2.0.4
Outdated
A window.fetch polyfill.
memoize-one
5.0.5
Outdated
A memoization library which only remembers the latest invocation
memoize
memoization
cache
performance
alexreardon
react-router
4.2.0
Outdated
Declarative routing for React
react
router
route
routing
history
+1
react-router-dom
4.2.0 - 4.2.2
Outdated
Declarative routing for React web applications
react
router
route
routing
history
+1
react-fast-compare
2.0.4
Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
fast
equal
react
compare
shouldComponentUpdate
+1
+12
warning
2.0.0 - 3.0.0
Outdated
A mirror of Facebook's Warning
warning
facebook
react
invariant
berkeleytrue
timers-browserify
2.0.10 - 2.0.12
timers module for browserify
timers
browserify
browser
+36
js-cookie
2.2.1
Outdated
A simple, lightweight JavaScript API for handling cookies
cookie
cookies
browser
amd
commonjs
+3
querystring-es3
0.2.1
Node's querystring module for all engines. (ES3 compat fork)
commonjs
query
querystring
spaintrain
shallowequal
1.1.0
Like lodash isEqualWith but for shallow equal.
shallowequal
shallow
equal
isequal
compare
+1
dashed
history
4.6.2 - 4.7.2
Outdated
Manage session history with JavaScript
history
location
mjackson
react-lifecycles-compat
3.0.4
Backwards compatibility polyfill for React class components
resize-observer-polyfill
1.5.1
A polyfill for the Resize Observer API
ResizeObserver
resize
observer
util
client
+3
que-etc
is-what
3.2.0 - 3.3.0
Outdated
JS type check (TypeScript supported) functions like `isPlainObject() isArray()` etc. A simple & small integration.
javascript
typescript
typechecker
check-type
javascript-type
+14
mesqueeb
styled-components
4.3.2
Outdated
CSS for the <Component> Age. Style components your way with speed, strong typing, and flexibility.
react
css
css-in-js
styled-components
styling
+1
i18next
2.2.0 - 15.1.3
Outdated
i18next internationalization framework
i18next
internationalization
i18n
translation
localization
+3
js-base64
3.2.0 - 3.3.3
Outdated
Yet another Base64 transcoder in pure-JS
base64
binary
dankogai
resolve-pathname
2.2.0
Outdated
Resolve URL pathnames using JavaScript
mjackson
value-equal
0.4.0
Outdated
Are these two JavaScript values equal?
mjackson
@hookform/resolvers
1.0.1 - 1.3.5
Outdated
React Hook Form validation resolvers: Yup, Joi, Superstruct, Zod, Vest, Class Validator, io-ts, Nope, computed-types, TypeBox, arktype and Typanion
scheme
validation
scheme-validation
hookform
react-hook-form
+14
exenv
1.2.1 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
react
browser
server
environment
env
+2
jedwatson
react-side-effect
1.1.4 - 1.1.5
Outdated
Create components whose prop changes map to a global side effect
react
component
side
effect
react-helmet
5.2.1
Outdated
A document head manager for React
react-helmet
nfl
react
document
head
+7
+2
@firebase/app
0.3.5
Outdated
The primary entrypoint to the Firebase JS SDK
+1
firebase
5.0.0 - 5.8.2
Outdated
Firebase JavaScript library for web and Node.js
authentication
database
Firebase
firebase
realtime
+3
+1
@firebase/auth
0.7.9
Outdated
The Firebase Authenticaton component of the Firebase JS SDK.
+1
babel-polyfill
6.16.0 - 6.26.0
Provides polyfills necessary for a full ES2015+ environment
universal-cookie
4.0.4
Outdated
Universal cookies for JavaScript
universal
isomophic
cookie
exon
stylis-rule-sheet
0.0.9 - 0.0.10
stylis plugin to extract individual rules to use with insertRule API
stylis
plugin
thysultan
fontfaceobserver
2.0.13
Outdated
Detect if web fonts are available
fontloader
fonts
font
font-face
web font
+2
bramstein
react-cookie
1.0.0 - 1.0.4
Outdated
Universal cookies for React
universal
isomophic
cookie
react
exon
merge-anything
2.4.0 - 2.4.1
Outdated
Merge objects & other types recursively. A simple & small integration.
javascript
merge
deepmerge
recursively
object-assign
+15
mesqueeb
react-swipeable
4.2.2
Outdated
React Swipe event handler hook
react swipe
react touch
react hook
touch
swipe
+3
+13
react-router-config
x.x.x
Static route config matching for React Router
react
router
route
routing
static routes
+2
react-loadable
5.4.0
Outdated
A higher order component for loading components with promises
detect-passive-events
1.0.4
Outdated
Detect if the browser supports passive events
detect
passive
passive events
rafgraph
react-lazy-load-image-component
1.3.2
Outdated
React Component to lazy load images using a HOC to track window scroll position.
react
react-component
lazyload
lazyloading
lazy-loading
+1
albertjuhe
deepcopy
2.0.0 - 2.1.0
deep copy data
sasaplus1
no-scroll
2.1.1
Disable the document's scrolling
scroll
scrolling
disable
modal
dialog
davidtheclark
@stimulus/core
0.6.0
Outdated
Stimulus JavaScript framework: Core library
dhh
react-responsive-modal
3.0.2 - 3.0.3
Outdated
A simple responsive and accessible react modal
react
responsive
modal
mobile
flex
leopradel
react-bootstrap-table-next
0.0.2 - 0.1.15
Outdated
Next generation of react-bootstrap-table
react
bootstrap
table
grid
react-component
allenfang
js-joda
1.8.0 - 1.11.0
a date and time library for javascript
date
time
timezone
lscache
1.2.0
Outdated
A simple library that emulates memcache functions using HTML5 localStorage
pamelafox
lottie-api
1.0.0 - 1.0.2
Outdated
A library to edit lottie-web animations dynamically
airnan
tg-core-redux
0.0.2 - 0.0.4
Outdated
tg-core-redux
+4
icon-font-loader
x.x.x
array-from
x.x.x
vikilitics
x.x.x
react-minimalist-portal
x.x.x
@viki-ui/theme
x.x.x
react-cookies
x.x.x
@viki-ui/gdpr
x.x.x
@viki-ui/helpers
x.x.x
@viki-ui/lazy-load
x.x.x
react-localization
x.x.x
localized-strings
x.x.x
ua-device-detector
x.x.x
re-tree
x.x.x
react-waterfall
x.x.x
soompi
x.x.x
@firebase/polyfill
x.x.x
@firebase/functions
x.x.x
@viki-ui/banners
x.x.x
@viki-ui/buttons
x.x.x
@viki-ui/extended
x.x.x
@viki-ui/forms
x.x.x
@viki-ui/modal
x.x.x
@viki-ui/tabs
x.x.x
@viki-ui/inline-search
x.x.x
honeybadger-js
x.x.x
Popular search queries
webpack.js.org
url
react-scripts
react
lottie-api
react-helmet-async
+7 packages
github.com
color-convert
@headlessui/react
hoist-non-react-statics
reactstrap
lit-html
+60 packages
pinterest.com
lodash
relay-runtime
react-relay
react-use
lodash-es
+51 packages
Popular packages
react
React is a JavaScript library for building user interfaces.
+6 634 websites
core-js
Standard library
+10 238 websites
es5-ext
ECMAScript extensions and shims
+10 229 websites
@babel/runtime
babel's modular runtime helpers
+8 352 websites
lodash
Lodash modular utilities.
+4 826 websites
axios
Promise based HTTP client for the browser and node.js
+4 742 websites