111 packages

Last scanned on Oct 27 at 07:02 PM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
4 KB
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
moment 2.19.0 - 2.25.1VulnerableOutdated
Parse, validate, manipulate, and display dates
uuid 7.0.0 - 8.0.0Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 0.0.0 - 0.0.1Outdated
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
qs 6.10.2 - 6.10.3Outdated
A querystring parser that supports nesting and arrays, with a depth limit
@babel/runtime 7.18.2 - 7.19.4Outdated
babel's modular runtime helpers
get-intrinsic 1.1.0 - 1.1.1Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
path-to-regexp 1.7.0 - 1.8.0Outdated
Express style path to RegExp utility
axios 0.26.1Outdated
Promise based HTTP client for the browser and node.js
cookie 0.4.2Outdated
HTTP server cookie parsing and serialization
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
object-inspect 1.12.0 - 1.12.1Outdated
string representations of objects in node and the browser
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
rxjs 6.6.2 - 6.6.7Outdated
Reactive Extensions for modern JavaScript
side-channel 1.0.4Outdated
Store information about any JS value in a side channel. Uses WeakMap if available.
has-property-descriptors 1.0.0Outdated
Does the environment have full property descriptor support? Handles IE 8's broken defineProperty/gOPD.
parse5 1.3.0 - 2.2.3Outdated
HTML parser and serializer.
define-properties 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
has-tostringtag 1.0.0Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From
regexp.prototype.flags 1.4.2 - 1.4.3Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
is-regex 1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
retry 0.13.1
Abstraction for exponential and custom retry strategies for failed operations.
is-date-object 1.0.4Outdated
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
eventemitter3 2.0.0 - 4.0.7Outdated
EventEmitter3 focuses on performance while maintaining a Node.js AND browser compatible interface.
functions-have-names 1.1.1 - 1.2.3
Does this JS environment support the `name` property on functions?
has 1.0.1 - 1.0.3Outdated shortcut
scheduler 0.15.0 - 0.23.0
Cooperative scheduler for the browser environment.
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
is-arguments 1.1.0Outdated
Is this an arguments object? It's a harder question than you think.
react 16.13.0 - 18.2.0
React is a JavaScript library for building user interfaces.
deep-equal 1.1.0 - 1.1.1Outdated
node's assert.deepEqual algorithm
dayjs 1.11.1 - 1.11.5Outdated
2KB immutable date time library alternative to Moment.js with the same modern API
object-is 1.1.0 - 1.1.5Outdated
ES2015-compliant shim for - differentiates between -0 and +0
clsx 1.2.0 - 1.2.1Outdated
A tiny (239B) utility for constructing className strings conditionally.
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
querystring 0.2.0Outdated
Node's querystring module for all engines.
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
react-transition-group 2.0.0 - 4.4.5
A react component toolset for managing animations
graphql 0.10.0 - 15.8.0Outdated
A Query Language and Runtime which can target any service.
whatwg-fetch 3.4.0 - 3.6.2Outdated
A window.fetch polyfill.
lodash.isequal 4.5.0
The Lodash method `_.isEqual` exported as a module.
tiny-invariant 0.0.2 - 1.3.1Outdated
A tiny invariant function
react-router 5.1.1 - 6.4.2Outdated
Declarative routing for React
is-promise 2.1.0 - 4.0.0
Test whether an object looks like a promises-a+ promise
react-router-dom 5.1.0 - 5.3.4Outdated
Declarative routing for React web applications
lodash-es 4.17.20 - 4.17.21
Lodash exported as ES modules.
redux 4.0.1 - 4.2.0Outdated
Predictable state container for JavaScript apps
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
crypto-browserify 1.0.9 - 2.0.0Outdated
implementation of crypto for the browser
reselect 2.3.0 - 4.1.6Outdated
Selectors for Redux.
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
react-redux 5.0.3 - 7.2.9Outdated
Official React bindings for Redux
history 4.0.0 - 4.10.1Outdated
Manage session history with JavaScript
url-join 4.0.0Outdated
Join urls and normalize as in path.join.
throttle-debounce 1.0.0 - 1.1.0Outdated
Throttle and debounce functions.
extract-files 6.0.0 - 8.1.0Outdated
A function to recursively extract files and their object paths within a value, replacing them with null in a deep clone without mutating the original value. FileList instances are treated as File instance arrays. Files are typically File and Blob instance
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
intl-messageformat 2.1.0 - 2.2.0Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
@reduxjs/toolkit 1.6.0 - 1.8.6Outdated
The official, opinionated, batteries-included toolset for efficient Redux development
@apollo/client 3.3.0 - 3.7.1Outdated
A fully-featured caching GraphQL client.
relay-runtime 13.2.0Outdated
A core runtime for building GraphQL-driven applications.
react-datepicker 0.59.0 - 1.6.0Outdated
A simple and reusable datepicker component for React
exenv 1.1.0 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
string-hash 1.1.1 - 1.1.3
fast string hashing function
react-side-effect 2.1.0 - 2.1.2
Create components whose prop changes map to a global side effect
@datadog/browser-core 1.2.2 - 1.25.1Outdated
Datadog browser core utilities.
react-helmet 6.0.0 - 6.1.0
A document head manager for React
react-intersection-observer 6.4.0 - 9.3.5Outdated
Monitor if a component is inside the viewport, using IntersectionObserver API
lit-element 3.0.1 - 3.2.2Outdated
A simple base class for creating fast, lightweight web components
react-beautiful-dnd 1.0.0 - 6.0.2Outdated
Beautiful and accessible drag and drop for lists with React
react-intl 2.1.5 - 2.9.0Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
intl-messageformat-parser 1.3.0 - 1.5.1Outdated
Parses ICU Message strings into an AST via JavaScript.
react-query 3.3.1 - 3.32.1Outdated
Hooks for managing, caching and syncing asynchronous and remote data in React
rc-trigger 4.3.0 - 4.3.4Outdated
base abstract trigger component for react
@material-ui/core 3.8.0 - 4.2.1Outdated
React components that implement Google's Material Design.
material-colors 1.2.2 - 1.2.6
Colors of Google's Material Design made available to coders
redux-devtools-extension 2.12.2Outdated
Wrappers for Redux DevTools Extension.
@auth0/auth0-spa-js 2.0.0Outdated
Auth0 SDK for Single Page Applications using Authorization Code Grant Flow with PKCE
diacritics 1.2.0 - 1.3.0
remove diacritics from strings
murmurhash 0.0.1 - 0.0.2Outdated
A Node.js module for the optimized JavaScript implementation of the MurmurHash algorithms.
@chakra-ui/theme 2.1.0 - 2.1.3Outdated
The default theme for chakra components
credit-card-type 8.1.0 - 8.3.0Outdated
A library for determining credit card type
react-calendar 2.0.0 - 2.13.4Outdated
Ultimate calendar for your React app.
ramda-adjunct 2.6.0 - 2.23.0Outdated
Ramda Adjunct is the most popular and most comprehensive set of utilities for use with Ramda, providing a variety of useful, well tested functions with excellent documentation.
react-scroll 1.5.5Outdated
A scroll component for React.js
react-dates 1.0.0 - 21.8.0
A responsive and accessible date range picker component built with React
react-native-web 0.0.62 - 0.17.7Outdated
React Native for Web
@loadable/component 5.15.0 - 5.15.2Outdated
React code splitting made easy.
connected-react-router 6.1.0 - 6.9.3
A Redux binding for React Router v4 and v5
redux-form 8.3.2 - 8.3.8Outdated
A higher order component decorator for forms using Redux and React
redux-actions 2.6.3 - 2.6.5Outdated
Flux Standard Action utlities for Redux
use-query-params 2.0.0 - 2.1.2Outdated
React Hook for managing state in URL query parameters with easy serialization.
redux-observable 1.0.0 - 1.2.0Outdated
RxJS based middleware for Redux. Compose and cancel async actions and more.
intl-relativeformat 2.2.0Outdated
Formats JavaScript dates to relative time strings.
analytics-utils 0.0.7 - 0.0.11Outdated
Analytics utility functions used by 'analytics' module
@splidejs/splide 4.0.0 - 4.1.3Outdated
Splide is a lightweight, flexible and accessible slider/carousel. No dependencies, no Lighthouse errors.
react-relay 13.2.0Outdated
A framework for building GraphQL-driven React applications.
mailcheck 1.1.1
A standalone module that suggests a right domain when your users misspell it in an email address.
aphrodite 1.2.4 - 1.2.5Outdated
Framework-agnostic CSS-in-JS with support for server-side rendering, browser prefixing, and minimum CSS generation
tti-polyfill 0.2.2
Polyfill for Time to Interactive. See
react-bootstrap-sweetalert 3.0.0 - 4.4.1Outdated
A variant of sweetalert for use with React and Bootstrap
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
web-speech-cognitive-services 4.0.0Outdated
Polyfill Web Speech API with Cognitive Services Speech-to-Text service
@wix/image-kit 1.14.0 - 1.24.0Outdated
Standard library for generating canonical URL's for optimally consuming images at Wix
react-gpt 2.0.1
A react display ad component using Google Publisher Tag
react-amphtml 3.1.0 - 4.0.2
Use amphtml components inside your React apps easily!