vistaprint.com 283 packages

Last scanned on Oct 27 at 07:42 PM
lodash-es 4.0.0 - 4.13.1VulnerableOutdated
Lodash exported as ES modules.
License
MIT
Vulnerabilities
Prototype Pollution in lodash
Affected versions >=0 <4.17.14
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.11
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.20
Version distribution in production
3 519
4.17.21
1 221
4.17.20
526
4.10.0
420
4.17.11
419
4.17.15
418
4.17.13
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
decode-uri-component 0.2.0VulnerableOutdated
A better decodeURIComponent
marked 3.0.5 - 3.0.8VulnerableOutdated
A markdown parser built for speed
engine.io-client 0.4.0 - 0.7.10VulnerableOutdated
Client for the realtime Engine
rauchg
darrachequesne
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
tslib 1.2.0 - 2.4.0Outdated
Runtime library for TypeScript helper functions
readable-stream 2.3.4 - 2.3.7Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
safe-buffer 5.1.0 - 5.2.1
Safer Node.js Buffer API
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
uuid 8.3.2Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is x.x.x
Brand checking of React Elements.
punycode x.x.x
A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.
inherits 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
qs 6.10.3Outdated
A querystring parser that supports nesting and arrays, with a depth limit
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
regenerator-runtime 0.13.7Outdated
Runtime for Regenerator-compiled generator and async functions.
@babel/runtime 7.14.0 - 7.16.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
is-extendable 1.0.0 - 1.0.1
Returns true if a value is a plain object, array or function.
get-intrinsic x.x.x
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
axios 0.21.4Outdated
Promise based HTTP client for the browser and node.js
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
object-inspect 1.10.3Outdated
string representations of objects in node and the browser
fast-deep-equal 0.1.0 - 1.0.0Outdated
Fast deep equal
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
isobject 3.0.0 - 4.0.0
Returns true if the value is an object and not an array or null.
@typescript-eslint/scope-manager 4.26.0 - 5.41.0Outdated
TypeScript scope analyser for ESLint
rxjs 7.5.0 - 7.5.2Outdated
Reactive Extensions for modern JavaScript
ieee754 1.1.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
is-plain-object 2.0.0 - 3.0.0Outdated
Returns true if an object was created by the `Object` constructor, or Object.create(null).
side-channel 1.0.4Outdated
Store information about any JS value in a side channel. Uses WeakMap if available.
util-deprecate x.x.x
The Node.js `util.deprecate()` function with browser support
object-assign 4.1.0 - 4.1.1
ES2015 `Object.assign()` ponyfill
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
domhandler 4.1.0 - 5.0.3
Handler for htmlparser2 that turns pages into a dom
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
is-buffer 1.1.0 - 1.1.3Outdated
Determine if an object is a Buffer
domelementtype 2.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
process-nextick-args 2.0.0 - 2.0.1
process.nextTick but always with args
cwmma
cwmma
core-js 3.13.0Outdated
Standard library
lodash.merge x.x.x
The Lodash method `_.merge` exported as a module.
util 0.10.0 - 0.12.5
Node.js's util module for all engines
xtend 4.0.1 - 4.0.2
extend like a boss
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
pako 2.0.0 - 2.0.4Outdated
zlib port to javascript - fast, modularized, with browser support
scheduler 0.20.2Outdated
Cooperative scheduler for the browser environment.
prop-types 15.7.0 - 15.7.2Outdated
Runtime type checking for React props and similar objects.
react 17.0.2Outdated
React is a JavaScript library for building user interfaces.
json-stringify-safe 5.0.1
Like JSON.stringify, but doesn't blow up on circular refs.
process x.x.x
process information for node.js and browsers
url-parse 1.5.9 - 1.5.10
Small footprint URL parser that works seamlessly across Node.js and browser environments
react-dom 17.0.2Outdated
React package for working with the DOM.
querystringify 2.2.0
Querystringify - Small, simple but powerful query string parser.
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
clsx 1.2.0 - 1.2.1Outdated
A tiny (239B) utility for constructing className strings conditionally.
@emotion/memoize 0.7.5 - 0.8.0Outdated
emotion's memoize utility
+1
emmatown
tkh44
emotion-release-bot
setimmediate x.x.x
A shim for the setImmediate efficient script yielding API
domenic
domenic
@aws-crypto/sha256-js 1.2.0 - 2.0.2Outdated
A pure JS implementation SHA256.
+5
amzn-oss
seebees
agray256
@aws-crypto/util 2.0.1 - 2.0.2Outdated
Helper functions
+5
amzn-oss
seebees
agray256
invariant 2.2.3 - 2.2.4
invariant
@emotion/unitless 0.7.2 - 0.8.0Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
dequal 2.0.0 - 2.0.3
A tiny (304B to 489B) utility for check for deep equality
classnames x.x.x
A simple utility for conditionally joining classNames together
stylis 4.0.0 - 4.0.5Outdated
A Light–weight CSS Preprocessor
andarist
thysultan
query-string x.x.x
Parse and stringify URL query strings
@emotion/is-prop-valid 0.8.8Outdated
A function to check whether a prop is valid for HTML and SVG elements
+1
emmatown
tkh44
emotion-release-bot
ua-parser-js 0.7.28Outdated
Detect Browser, Engine, OS, CPU, and Device type/model from User-Agent & Client Hints data. Supports browser & node.js environment
@emotion/hash 0.8.0 - 0.9.0Outdated
A MurmurHash2 implementation
+1
emmatown
tkh44
emotion-release-bot
lodash.get 4.4.1 - 4.4.2
The lodash method `_.get` exported as a module.
@aws-sdk/util-utf8-browser 3.0.0 - 3.186.0Outdated
A browser UTF-8 string <-> UInt8Array converter
+2
mattsb42-aws
kuhe
amzn-oss
@emotion/serialize 1.0.2 - 1.1.1Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
@emotion/utils 1.0.0 - 1.2.0Outdated
internal utils for emotion
+1
emmatown
tkh44
emotion-release-bot
lodash.isequal 4.5.0
The Lodash method `_.isEqual` exported as a module.
immer 7.0.7 - 9.0.16Outdated
Create your next immutable state by mutating the current one
strict-uri-encode 2.0.0
A stricter URI encode adhering to RFC 3986
@emotion/cache x.x.x
emotion's cache
+1
emmatown
tkh44
emotion-release-bot
@emotion/sheet 1.1.0 - 1.2.1Outdated
emotion's stylesheet
+1
emmatown
tkh44
emotion-release-bot
react-router 0.5.3 - 0.9.3Outdated
Declarative routing for React
next-tick 0.2.2Outdated
Environment agnostic nextTick polyfill
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
stream-http 2.8.2 - 2.8.3Outdated
Streaming http in the browser
timers-browserify 2.0.6 - 2.0.12
timers module for browserify
https-browserify x.x.x
https module compatability for browserify
js-cookie 3.0.1Outdated
A simple, lightweight JavaScript API for handling cookies
use-sync-external-store x.x.x
Backwards compatible shim for React's useSyncExternalStore. Works with any React that supports hooks.
acdlite
gnoff
react-bot
builtin-status-codes x.x.x
The map of HTTP status codes from the builtin http module
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
filter-obj 1.1.0Outdated
Filter object keys and values into a new object
babel-runtime 4.0.1 - 6.9.0Outdated
babel selfContained runtime
hzoo
loganfsmyth
existentialism
fbjs x.x.x
A collection of utility libraries used by other Facebook JS projects
+5
zpao
eliwhite
yungsters
history 4.6.0 - 4.7.2Outdated
Manage session history with JavaScript
md5 x.x.x
js function for hashing messages with MD5
coolaj86
pvorb
polished 3.0.0 - 3.4.4Outdated
A lightweight toolset for writing styles in Javascript.
style-to-object 0.2.3 - 0.3.0Outdated
Parse CSS inline style to JavaScript object.
crypt 0.0.0 - 0.0.2
utilities for encryption and hashing
pvorb
pvorb
charenc 0.0.0 - 0.0.2
character encoding utilities
pvorb
pvorb
is-retry-allowed 1.2.0Outdated
Check whether a request can be retried based on the `error.code`
jwt-decode 3.0.0 - 3.1.2Outdated
Decode JWT tokens, mostly useful for browser applications.
to-arraybuffer 1.0.1
Get an ArrayBuffer from a Buffer as fast as possible
split-on-first 1.0.0 - 1.1.0Outdated
Split a string on the first occurance of a given separator
inline-style-parser 0.1.0 - 0.1.1Outdated
An inline style parser.
resize-observer-polyfill 1.5.1
A polyfill for the Resize Observer API
yup 0.32.0 - 0.32.11Outdated
Dead simple Object schema validation
monastic.panic
monastic.panic
mitt 1.1.3 - 1.2.0Outdated
Tiny 200b functional Event Emitter / pubsub.
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
dompurify x.x.x
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It's written in JavaScript and works in all modern browsers (Safari, Opera (15+), Internet Explorer (10+), Firefox and Chrome - as well as almost anything else usin
global 2.0.4 - 4.4.0
Require global variables
jerrysievert
mattesch
raynos
use-isomorphic-layout-effect x.x.x
A React helper hook for scheduling a layout effect with a fallback to a regular effect for environments where layout effects should not be used (such as server-side rendering).
andarist
andarist
mustache 3.2.1Outdated
Logic-less {{mustache}} templates with JavaScript
@aws-sdk/util-uri-escape 3.183.0 - 3.188.0Outdated
[![NPM version](https://img.shields.io/npm/v/@aws-sdk/util-uri-escape/latest.svg)](https://www.npmjs.com/package/@aws-sdk/util-uri-escape) [![NPM downloads](https://img.shields.io/npm/dm/@aws-sdk/util-uri-escape.svg)](https://www.npmjs.com/package/@aws-sd
+2
amzn-oss
aws-sdk-bot
kuhe
@juggle/resize-observer 3.3.0 - 3.3.1Outdated
Polyfills the ResizeObserver API and supports box size options from the latest spec
react-error-boundary x.x.x
Simple reusable React error boundary component
kentcdodds
brianvaughn
framer-motion 3.10.6Outdated
A simple and powerful JavaScript animation library
@emotion/css 11.0.0 - 11.10.5Outdated
The Next Generation of CSS-in-JS.
axios-retry 3.0.0 - 3.2.0Outdated
Axios plugin that intercepts failed requests and retries them whenever posible.
softonic
softonic
object.omit 3.0.0
Return a copy of an object excluding the given key, or array of keys. Also accepts an optional filter function as the last argument.
custom-event 1.0.1
Cross-browser `CustomEvent` constructor
react-textarea-autosize 8.0.0 - 8.3.4Outdated
textarea component for React which grows with content
fuse.js 5.1.0 - 6.6.2Outdated
Lightweight fuzzy-search
framesync 5.2.0 - 5.3.0Outdated
A frame-synced render loop for JavaScript
popmotion
popmotion
react-focus-lock 2.3.0 - 2.9.1Outdated
It is a trap! (for a focus)
use-latest 1.0.0 - 1.2.1
A React helper hook for storing latest value in ref object (updated in useEffect's callback).
andarist
andarist
use-composed-ref 1.0.0 - 1.3.0
React hook which creates a ref function from given refs. Useful when using forwardRef.
andarist
andarist
react-side-effect x.x.x
Create components whose prop changes map to a global side effect
react-helmet 6.0.0 - 6.1.0
A document head manager for React
react-intersection-observer 8.31.1 - 8.32.5Outdated
Monitor if a component is inside the viewport, using IntersectionObserver API
lit-element 3.0.1 - 3.2.2Outdated
A simple base class for creating fast, lightweight web components
+11
aomarks
emarquez
sorvell
algoliasearch x.x.x
A fully-featured and blazing-fast JavaScript API client to interact with Algolia API.
+7
millotp
shortcuts
haroenv
react-query 3.38.1 - 3.39.1Outdated
Hooks for managing, caching and syncing asynchronous and remote data in React
tannerlinsley
tkdodo
@react-aria/utils 3.4.0 - 3.14.0Outdated
Spectrum UI components in React
devongovett
aspro83
popmotion 9.3.1 - 9.3.5Outdated
The animator's toolbox
style-value-types 4.1.0 - 4.1.4Outdated
Parsers, transformers and tests for special value types, eg: %, hex codes etc.
html-react-parser 1.2.8 - 1.2.9Outdated
HTML to React parser.
html-dom-parser x.x.x
HTML to DOM parser.
mobx 4.15.0 - 6.6.2Outdated
Simple, scalable state management.
react-property 1.0.1 - 1.0.2Outdated
HTML and SVG DOM property configs used by React.
style-to-js 1.1.0Outdated
Parses CSS inline style to JavaScript object (camelCased).
use-debounce 5.2.0 - 8.0.4Outdated
Debounce hook for react
mobx-react-lite 3.3.0 - 3.4.0Outdated
Lightweight React bindings for MobX based on React 16.8+ and Hooks
detect-browser 4.0.1 - 4.8.0Outdated
Unpack a browser type and version from the useragent string
use-subscription x.x.x
Reusable hooks
+1
gnoff
fb
sophiebits
@auth0/auth0-spa-js 2.0.0Outdated
Auth0 SDK for Single Page Applications using Authorization Code Grant Flow with PKCE
style-inject 0.3.0
Inject style tag to document head.
@reach/router 1.3.4
Next generation Routing for React.
murmurhash x.x.x
A Node.js module for the optimized JavaScript implementation of the MurmurHash algorithms.
perezd
perezd
use-deep-compare-effect 1.8.0 - 1.8.1
It's react's useEffect hook, except using deep comparison on the inputs, not reference equality
kentcdodds
kentcdodds
search-insights x.x.x
Library for reporting click, conversion and view metrics using the Algolia Insights API
+4
jasonberry
dhaya.b
instantsearch-bot
react-content-loader 5.0.0 - 6.2.0Outdated
SVG-Powered component to easily create placeholder loadings (like Facebook cards loading)
canvas-confetti 0.2.0 - 1.6.0Outdated
performant confetti animation in the browser
gatsby-legacy-polyfills 0.7.1Outdated
Polyfills for legacy browsers
+3
kathmbeck
pieh
tylerbarnes
es-cookie x.x.x
A JavaScript module for handling cookies
gatsby 2.24.0 - 2.24.61Outdated
Blazing fast modern site generator for React
bootstrap-vue 1.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
gatsby-link 2.6.1 - 2.11.0Outdated
An enhanced Link component for Gatsby sites with support for resource prefetching
gatsby-react-router-scroll 3.4.0 - 3.7.0Outdated
React Router scroll management forked from https://github.com/ytase/react-router-scroll for Gatsby
shallow-compare 1.2.1 - 1.2.2
Stand alone shallowCompare for use in libraries that support shouldComponentUpdate
@optimizely/optimizely-sdk x.x.x
JavaScript SDK for Optimizely Feature Experimentation, Optimizely Full Stack (legacy), and Optimizely Rollouts
optimizely-fullstack
optimizely-fullstack
detect-passive-events x.x.x
Detect if the browser supports passive events
detect-it x.x.x
Detect if a device is mouse only, touch only, or hybrid
@optimizely/js-sdk-utils x.x.x
Optimizely Full Stack Utils
optimizely-fullstack
optimizely-fullstack
@optimizely/js-sdk-event-processor x.x.x
Optimizely Full Stack Event Processor
optimizely-fullstack
optimizely-fullstack
@optimizely/js-sdk-logging x.x.x
Optimizely Full Stack Core Logging
optimizely-fullstack
optimizely-fullstack
store 2.0.12
A localStorage wrapper for all browsers without using cookies or flash. Uses localStorage, globalStorage, and userData behavior under the hood
marcuswestin
marcuswestin
@optimizely/js-sdk-datafile-manager x.x.x
Optimizely Full Stack Datafile Manager
optimizely-fullstack
optimizely-fullstack
react-countdown 2.2.0 - 2.2.2Outdated
A customizable countdown component for React.
@use-it/event-listener 0.1.5 - 0.1.7
A custom React Hook that provides a useEventListener.
use-persisted-state 0.3.3
A custom React Hook that provides a multi-instance, multi-tab/browser shared and persistent state.
@mikaelkristiansson/domready 1.0.10 - 1.0.11
modern domready
mikaelkristiansson87
mikaelkristiansson87
hoverintent 1.0.3Outdated
Fire mouse events when the user intends it
davidtheclark
tristen
web-speech-cognitive-services 4.0.0Outdated
Polyfill Web Speech API with Cognitive Services Speech-to-Text service
@wardpeet/gatsby-plugin-static-site 0.2.3 - 0.3.0
A plugin that disables client side routing for gatsby
@team-griffin/uteals 1.0.0Outdated
Utilities for Tealium
+1
christierobson
quagliero
jshthornton
@vp/recommendations x.x.x
@vp/vp-js-token-engine x.x.x
@vp/vp-tokenized-fragment x.x.x
@rendering/vortex-core x.x.x
@vp/sumo-logger x.x.x
@vp/ft-reader-core x.x.x
@vp/auth-react x.x.x
@vp/poe-client x.x.x
@vp/logutil x.x.x
@vp/tenant-resolution x.x.x
@vp/ab-test-cookie x.x.x
is-eu-member x.x.x
@vp/culture-resolution x.x.x
@vp/cookie-consent-client-reader x.x.x
@vp/uds-client x.x.x
@vp/wes-client x.x.x
@design-stack-ct/utility-react x.x.x
@design-stack-ct/ida-framework x.x.x
@design-stack-ct/utility-core x.x.x
lodash.round x.x.x
colorthief x.x.x
@design-stack-ct/design-engine-react-components x.x.x
@design-stack-ct/cimdoc-state-manager x.x.x
@design-stack-ct/cdif-color-sdk x.x.x
@design-stack-ct/font-sdk x.x.x
@design-stack-ct/embroidery-client x.x.x
@design-stack-ct/documents-sdk x.x.x
@design-stack-ct/preview-sdk x.x.x
react-use-gesture x.x.x
@design-stack-ct/interactive-design-engine-core x.x.x
mobx-utils x.x.x
@design-stack-ct/image-mind-client x.x.x
@design-stack-ct/item-collage-sdk x.x.x
@design-stack-ct/cimdoc-testing-utils x.x.x
@design-stack-vista/wordart-functionalities x.x.x
@design-stack-vista/error-helpers x.x.x
@vp/easel-calcifer-client x.x.x
@vp/easel-calcifer-provider-react x.x.x
@vp/easel-document-provider-react x.x.x
@design-stack-vista/a11y x.x.x
@design-stack-vista/pan-helpers x.x.x
@rooks/use-previous x.x.x
@vp/easel-ida-react x.x.x
@vp/easel-chrome-react x.x.x
@design-stack-vista/siteflow-client x.x.x
@design-stack-vista/stars-client x.x.x
@xstate/fsm x.x.x
@xstate/react x.x.x
@vp/easel-design-experience-react x.x.x
react-async-hook x.x.x
@design-stack-vista/studio-chrome x.x.x
@vp/easel-purcs-client x.x.x
@vp/easel-preview-react x.x.x
@vp/easel-icons-react x.x.x
@vp/easel-preview-experience-react x.x.x
@vp/error-handling x.x.x
@vp/vortex-react x.x.x
@vp/simple-configurator x.x.x
@vp/cross-sell-studio x.x.x
@vp/ft-context-reader x.x.x
@vp/ft-reader x.x.x
@vp/ab-impression x.x.x
base64url x.x.x
detect-hover x.x.x
detect-pointer x.x.x
detect-touch-events x.x.x
@vp/react-cursor-position x.x.x
clamp x.x.x
@vp/react-image-magnify x.x.x
react-required-if x.x.x
@vp/nano-studio x.x.x
@vp/tracking x.x.x
window-load x.x.x
@design-stack-vp/react-vortex x.x.x
@vp/track-user-interaction x.x.x
@rendering/vortex-product-loader x.x.x
@rendering/vortex-paper-products x.x.x
@rendering/vortex-modeled-products x.x.x
@rendering/vortex-canvas-prints x.x.x
@vp/ab-reader x.x.x
@vp/react-pricing-context x.x.x
@vp/wrangler-data-source x.x.x
liquidjs x.x.x
@vp/pricing-context-module x.x.x
@vp/sitewide-promo-bar x.x.x
@vp/audience-for-frontend x.x.x
@vp/gatsby-pages-issues-tracker-plugin x.x.x
@vp/react-product-preview x.x.x
@vp/react-new-relic-browser x.x.x
@vp/channel-tracking x.x.x
@vp/gatsby-theme-performance x.x.x
@vp/fido x.x.x
react-cool-inview x.x.x
react-portal-tooltip x.x.x
localized-strings x.x.x
@vp/omnisearch x.x.x
@vp/email-subscription-component x.x.x
@vp/react-bookends x.x.x
@vp/bookends-ab-testing-utilities x.x.x
@vp/ctc-reader x.x.x
@vp/cache-agent x.x.x
@vp/consent-manager x.x.x
@vp/auth x.x.x
three x.x.x
@vp/cart-client x.x.x
@vp/visage x.x.x
gatsby-plugin-react-decorators x.x.x