142 packages

Last scanned on Jan 19 at 11:45 AM
url-parse 1.4.3VulnerableOutdated
Small footprint URL parser that works seamlessly across Node.js and browser environments
3 KB
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Affected versions >=0 <1.5.9
Authorization bypass in url-parse
Affected versions >=0 <1.5.6
Path traversal in url-parse
Affected versions >=0 <1.5.0
Open redirect in url-parse
Affected versions >=0 <1.5.2
Authorization Bypass Through User-Controlled Key in url-parse
Affected versions >=0 <1.5.8
url-parse Incorrectly parses URLs that include an '@'
Affected versions >=0 <1.5.7
Improper Validation and Sanitization in url-parse
Affected versions >=0 <1.4.5
Matched Modules
Version distribution in production
react 0.10.0 - 0.13.3VulnerableOutdated
React is a JavaScript library for building user interfaces.
marked 0.4.0VulnerableOutdated
A markdown parser built for speed
prismjs 1.14.0 - 1.15.0VulnerableOutdated
Lightweight, robust, elegant syntax highlighting. A spin-off project from Dabblet.
trim 0.0.1VulnerableOutdated
Trim string whitespace
sanitize-html 1.18.5 - 1.19.0VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
ajv 5.1.5 - 5.2.0VulnerableOutdated
Another JSON Schema Validator
minimist 1.2.0VulnerableOutdated
parse argument options
elliptic 6.5.2 - 6.5.3VulnerableOutdated
EC cryptography
markdown-it 2.0.0 - 3.1.0VulnerableOutdated
Markdown-it - modern pluggable markdown parser.
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
source-map 0.6.1Outdated
Generates and consumes source maps
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
escape-string-regexp 1.0.0 - 1.0.5Outdated
Escape RegExp special characters
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
json-schema-traverse 0.3.0 - 0.3.1Outdated
Traverse JSON Schema passing each schema object to callback
inherits 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
entities 1.1.1 - 1.1.2Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.0.0 - 7.12.18Outdated
babel's modular runtime helpers
core-util-is 1.0.2 - 1.0.3
The `*` functions introduced in Node v0.12.
is-plain-obj 1.1.0Outdated
Check if a value is a plain object
domutils 1.5.1Outdated
Utilities for working with htmlparser2's dom
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
dom-serializer 0.1.0Outdated
render domhandler DOM nodes to a string
domhandler 2.4.0 - 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
is-buffer 1.1.4 - 1.1.6Outdated
Determine if an object is a Buffer
domelementtype 1.1.1 - 1.3.1Outdated
all the types of nodes in htmlparser2's dom
core-js 2.6.1Outdated
Standard library
util 0.10.0 - 0.12.5
Node.js's util module for all engines
htmlparser2 3.10.0 - 3.10.1Outdated
Fast & forgiving HTML/XML parser
extend 3.0.2
Port of jQuery.extend for node.js and the browser
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
scheduler 0.9.0 - 0.14.0Outdated
Cooperative scheduler for the browser environment.
prop-types 15.7.0 - 15.7.2Outdated
Runtime type checking for React props and similar objects.
co 4.6.0
generator async control flow goodness
react-dom 16.4.1 - 16.4.2Outdated
React package for working with the DOM.
querystringify 2.0.0 - 2.1.0Outdated
Querystringify - Small, simple but powerful query string parser.
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
repeat-string 1.6.0 - 1.6.1
Repeat the given string n times. Fastest implementation for repeating a string.
html-entities 2.0.4 - 2.3.3Outdated
Fastest HTML entities encode/decode library.
axobject-query 0.1.0 - 3.1.1Outdated
Programmatic access to information about the AXObject Model
unist-util-visit-parents 2.0.1Outdated
unist utility to recursively walk over nodes, with ancestral information
unist-util-is 2.1.0 - 2.1.3Outdated
unist utility to check if a node passes a test
path-browserify 0.0.0 - 0.0.1Outdated
the path module from node core for browsers
unist-util-visit 1.4.0 - 2.0.3Outdated
unist utility to visit nodes
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
classnames 2.2.6Outdated
A simple utility for conditionally joining classNames together
lodash.camelcase 4.2.0 - 4.3.0
The lodash method `_.camelCase` exported as a module.
unist-util-stringify-position 1.1.1 - 1.1.2Outdated
unist utility to serialize a node, position, or point as a human readable location
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
ramda 0.26.0 - 0.27.2Outdated
A practical functional library for JavaScript programmers.
vfile-message 1.0.0 - 2.0.4Outdated
vfile utility to create a virtual message
unified 6.2.0 - 7.0.0Outdated
parse, inspect, transform, and serialize content through syntax trees
asn1.js 4.6.0 - 4.10.1Outdated
ASN.1 encoder and decoder
hash-base 3.0.4 - 3.1.0
abstract base class for hash-streams
vfile 2.1.0 - 4.2.0Outdated
Virtual file format for text processing
hash.js 1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
react-router 6.4.0 - 6.7.0Outdated
Declarative routing for React
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
space-separated-tokens 1.1.0 - 1.1.2Outdated
Parse and stringify space separated tokens
des.js 1.0.1Outdated
DES implementation
array-uniq 0.1.1 - 1.0.3Outdated
Create an array without duplicates
md5.js 1.1.0 - 1.3.5
node style md5 on pure JavaScript
pbkdf2 3.1.0 - 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
cipher-base 1.0.4
abstract base class for crypto-streams
parse-asn1 5.1.4 - 5.1.5Outdated
utility library for parsing asn1 files for use with browserify-sign.
browserify-sign 2.4.0 - 2.8.0Outdated
adds node crypto signing for browsers
browserify-aes 0.4.0 - 0.8.1Outdated
aes, for browserify
remark-parse 5.0.0Outdated
remark plugin to add support for parsing markdown input
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 3.0.0 - 4.0.1Outdated
RSA for browserify
timers-browserify 2.0.9Outdated
timers module for browserify
create-ecdh 3.0.0 - 4.0.4
createECDH but browserifiable
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
diffie-hellman 1.1.2Outdated
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
miller-rabin 1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
parse-entities 1.1.1 - 1.1.2Outdated
Parse HTML character references
trough 1.0.3 - 1.0.5Outdated
`trough` is middleware
randomfill 1.0.0 - 1.0.4
random fill from browserify stand alone
vm-browserify 0.0.1 - 1.1.2
vm module for the browser
bail 1.0.0 - 2.0.2
Throw a given error
mdurl 0.0.1 - 1.0.1Outdated
URL utilities for markdown-it
character-entities-legacy 2.0.0Outdated
List of legacy HTML named character references that don’t need a trailing semicolon
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
is-alphabetical 1.0.0 - 2.0.0Outdated
Check if a character is alphabetical
is-decimal 1.0.0 - 2.0.0Outdated
Check if a character is decimal
is-hexadecimal 1.0.0 - 2.0.0Outdated
Check if a character is hexadecimal
character-reference-invalid 2.0.0 - 2.0.1
Map of invalid numeric character references to their replacements, according to HTML
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
property-information 5.0.0 - 5.0.1Outdated
Info on the properties and attributes of the web platform
mdast-util-definitions 1.2.2 - 3.0.1Outdated
mdast utility to find definition nodes in a tree
@xmldom/xmldom 0.7.0 - 0.8.6Outdated
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
comma-separated-tokens 1.0.2 - 1.0.5Outdated
Parse and stringify comma-separated tokens
json-stable-stringify 1.0.1 - 1.0.2Outdated
deterministic JSON.stringify() with custom sorting to get deterministic hashes from stringified results
jsonify 0.0.0Outdated
JSON without touching any globals
style-to-object 0.2.0 - 0.2.2Outdated
Parse CSS inline style to JavaScript object.
replace-ext 0.0.1 - 1.0.0Outdated
Replaces a file extension with another one.
ccount 1.0.1 - 1.0.4Outdated
Count how often a character (or substring) is used in a string
mdast-util-to-hast 4.0.0Outdated
mdast utility to transform to hast
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
longest-streak 2.0.1 - 2.0.4Outdated
Count the longest repeating streak of a substring
css 2.2.2 - 3.0.0
CSS parser / stringifier
unist-util-remove-position 1.1.0 - 3.0.0Outdated
unist utility to remove positions from a tree
vfile-location 2.0.0 - 3.0.1Outdated
vfile utility to convert between positional (line and column-based) and offset (range-based) locations
unist-util-generated 1.0.0 - 1.1.5Outdated
unist utility to check if a node is generated
markdown-table 1.1.2Outdated
Generate a markdown (GFM) table
lodash.escaperegexp 4.1.2
The lodash method `_.escapeRegExp` exported as a module.
web-namespaces 2.0.0 - 2.0.1
Map of web namespaces
remark-stringify 5.0.0Outdated
remark plugin to add support for serializing markdown
unist-builder 1.0.3 - 2.0.0Outdated
unist utility to create a new trees with a nice syntax
collapse-white-space 1.0.0 - 2.0.0Outdated
Collapse white space
unherit 1.1.0 - 1.1.3Outdated
Create a subclass that can be modified without affecting the super class
@angular/forms 0.1.0 - 2.4.10Outdated
Angular - directives and services for creating forms
trim-trailing-lines 1.1.0 - 1.1.3Outdated
Remove final line feeds from a string
is-whitespace-character 1.0.0 - 2.0.1
Check if a character is a whitespace character
state-toggle 1.0.0 - 2.0.1Outdated
Enter/exit a state
markdown-escapes 1.0.0 - 1.0.4Outdated
Legacy list of escapable characters in markdown
is-word-character 1.0.0 - 2.0.1
Check if a character is a word character
formik 1.0.0 - 2.2.9Outdated
Build forms in React, without the tears
hast-to-hyperscript 5.0.0 - 6.0.0Outdated
Deprecated: use [`hast-util-to-jsx-runtime`][hast-util-to-jsx-runtime] instead, which is much better :)
exenv 1.1.0 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
react-side-effect 1.1.5Outdated
Create components whose prop changes map to a global side effect
react-helmet 5.2.0 - 5.2.1Outdated
A document head manager for React
hast-util-sanitize 1.2.0 - 1.2.1Outdated
hast utility to sanitize nodes
@reach/router 1.3.1 - 1.3.4
Next generation Routing for React.
srcset 1.0.0Outdated
Parse and stringify the HTML `<img>` srcset attribute
html-to-react 1.3.1 - 1.4.1Outdated
A lightweight library that converts raw HTML to a React DOM structure.
gatsby 1.9.149 - 5.4.2Outdated
Blazing fast modern site generator for React
gatsby-link 2.4.4 - 2.11.0Outdated
An enhanced Link component for Gatsby sites with support for resource prefetching
gatsby-react-router-scroll 2.1.22 - 2.3.1Outdated
React Router scroll management forked from for Gatsby
@mapbox/hast-util-table-cell-style 0.1.3 - 0.2.0Outdated
Transform deprecated styling attributes on HAST table cells to inline styles
scroll-behavior 0.9.7 - 0.11.0
Pluggable browser scroll management
@mikaelkristiansson/domready 1.0.10 - 1.0.11
modern domready
react-redux-loading-bar 3.0.1 - 3.0.2Outdated
Simple Loading Bar for Redux and React
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically