← Back to Report

All Findings

github.com/Risk-Guard/public-test · 380 findings across 211 packages

Findings

380 findings across 211 packages

Critical 5 packages

Package Check Detail
importlib-metadata PACKAGE_INSTALL_SCRIPTS artifact pypi/importlib-metadata: importlib_metadata-8.7.1/tests/data/sources/example/setup.py
SOURCE_NO_LICENSE No license file found in source repository
rdoc VULN_HISTORICAL_SEVERE CVE-2021-31799 (GHSA-ggxm-pgc9-g7fp) 7.0 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.0 HIGH)
SOURCE_NO_LICENSE No license file found in source repository
f-ask PACKAGE_NAME_MISMATCH
  • Package name: pypi/f-ask
  • Source Code: https://github.com/pallets/flask
  • Packages found in source (1 total): Flask (pyproject.toml)
PACKAGE_UNRELEASED_CHANGES
  • pypi/f-ask: Latest human commit (2026-02-19) is 2544 days ahead of last release (2019-03-04).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE pypi/f-ask@1.1.dev0: Package last released 2550 days ago (7.0 years)
zipp SOURCE_NO_LICENSE No license file found in source repository
minitest SOURCE_PACKAGE_NAME_UNEXPORTED Scanned source tree but found no package definition files
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
SOURCE_NO_LICENSE No license file found in source repository

npm 77 of 92 packages with findings

Package Check Detail
inherits @2.0.4 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
PACKAGE_LICENSE_MISMATCH npm/inherits: ISC not satisfied by any available license
PACKAGE_UNRELEASED_CHANGES
  • npm/inherits: Latest human commit (2025-10-25) is 2319 days ahead of last release (2019-06-19).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/inherits@2.0.4: Package last released 2441 days ago (6.7 years)
forwarded @0.2.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
VULN_HISTORICAL_SEVERE CVE-2017-16118 (GHSA-mpcf-4gmh-23w8) 7.5 HIGH from nvd@nist.gov
PACKAGE_UNRELEASED_CHANGES
  • npm/forwarded: Latest human commit (2025-07-23) is 1513 days ahead of last release (2021-05-31).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/forwarded@0.2.0: Package last released 1728 days ago (4.7 years)
ee-first @1.1.1 PACKAGE_UNRELEASED_CHANGES
  • npm/ee-first: Latest human commit (2018-06-05) is 1107 days ahead of last release (2015-05-25).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/ee-first@1.1.1: Package last released 3927 days ago (10.8 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_REPO_ABANDONED Latest human commit: 2018-06-05
escape-html @1.0.3 PACKAGE_UNRELEASED_CHANGES
  • npm/escape-html: Latest human commit (2019-01-10) is 1227 days ahead of last release (2015-09-01).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/escape-html@1.0.3: Package last released 3828 days ago (10.5 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_REPO_ABANDONED Latest human commit: 2019-01-10
unpipe @1.0.0 PACKAGE_UNRELEASED_CHANGES
  • npm/unpipe: Latest human commit (2018-06-28) is 1110 days ahead of last release (2015-06-14).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/unpipe@1.0.0: Package last released 3907 days ago (10.7 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_ABANDONED Latest human commit: 2018-06-28
y18n @5.0.8 VULN_HISTORICAL_SEVERE CVE-2020-7774 (GHSA-c4w7-xm78-47vh) 9.8 CRITICAL from nvd@nist.gov (Secondary: report@snyk.io: 7.3 HIGH)
PACKAGE_UNRELEASED_CHANGES
  • npm/y18n: Latest human commit (2022-11-11) is 583 days ahead of last release (2021-04-07).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/y18n@5.0.8: Package last released 1783 days ago (4.9 years)
SOURCE_REPO_STALE Latest human commit: 2022-11-11
utils-merge @1.0.1 PACKAGE_UNRELEASED_CHANGES
  • npm/utils-merge: Latest human commit (2020-06-16) is 1000 days ahead of last release (2017-09-20).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/utils-merge@1.0.1: Package last released 3080 days ago (8.4 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_ABANDONED Latest human commit: 2020-06-16
depd @2.0.0 PACKAGE_UNRELEASED_CHANGES
  • npm/depd: Latest human commit (2021-11-12) is 1112 days ahead of last release (2018-10-26).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/depd@2.0.0: Package last released 2677 days ago (7.3 years)
SOURCE_REPO_STALE Latest human commit: 2021-11-12
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
array-flatten @1.1.1 PACKAGE_UNRELEASED_CHANGES
  • npm/array-flatten: Latest human commit (2023-12-07) is 1477 days ahead of last release (2019-11-21).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/array-flatten@3.0.0: Package last released 2288 days ago (6.3 years)
SOURCE_REPO_STALE Latest human commit: 2023-12-07
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
methods @1.1.2 PACKAGE_STALE_RELEASE npm/methods@1.1.2: Package last released 3691 days ago (10.1 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
PACKAGE_UNRELEASED_CHANGES
  • npm/methods: Latest human commit (2025-06-05) is 3426 days ahead of last release (2016-01-18).
  • Source code has new human commits not released to package registry.
kind-of @3.2.2 SOURCE_REPO_STALE Latest human commit: 2023-11-02
VULN_HISTORICAL_SEVERE CVE-2019-20149 (GHSA-6c8f-qphg-qjgp) 7.5 HIGH from nvd@nist.gov
PACKAGE_UNRELEASED_CHANGES
  • npm/kind-of: Latest human commit (2023-11-02) is 1386 days ahead of last release (2020-01-16).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/kind-of@6.0.3: Package last released 2232 days ago (6.1 years)
range-parser @1.2.1 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
PACKAGE_UNRELEASED_CHANGES
  • npm/range-parser: Latest human commit (2026-01-23) is 2449 days ahead of last release (2019-05-11).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/range-parser@1.2.1: Package last released 2480 days ago (6.8 years)
lodash VULN_HISTORICAL_SEVERE
  • CVE-2020-8203 (GHSA-p6mc-m468-83gw) 7.4 HIGH from nvd@nist.gov
  • CVE-2021-41720 (GHSA-8p5q-j9m2-g8wr) 9.8 low
  • CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) 7.2 HIGH from nvd@nist.gov (Secondary: report@snyk.io: 7.2 HIGH)
  • CVE-2019-10744 (GHSA-jf85-cpcp-j695) 9.1 CRITICAL from nvd@nist.gov
LICENSE_MODIFIED
  • LICENSE: MIT - 677 extra characters: 'based on underscore.js, copyright jeremy ashkenas, documentcloud and investigative reporters and editors <https://underscorejs.org/> this software consists of voluntary contributions made by many indi...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/LICENSE)
  • vendor/firebug-lite/license.txt: BSD-Source-Code - 243 extra characters: 'software license agreement (bsd license) redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or othe...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
LICENSE_NOT_APPROVED BSD-Source-Code (vendor/firebug-lite/license.txt) (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
get-caller-file @2.0.5 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_REPO_ABANDONED Latest human commit: 2019-03-09
PACKAGE_STALE_RELEASE npm/get-caller-file@2.0.5: Package last released 2543 days ago (7.0 years)
destroy @1.2.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
PACKAGE_STALE_RELEASE npm/destroy@1.2.0: Package last released 1437 days ago (3.9 years)
SOURCE_REPO_STALE Latest human commit: 2022-03-20
etag @1.8.1 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
PACKAGE_UNRELEASED_CHANGES
  • npm/etag: Latest human commit (2025-07-23) is 2870 days ahead of last release (2017-09-13).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/etag@1.8.1: Package last released 3085 days ago (8.5 years)
safe-buffer @5.2.1 PACKAGE_STALE_RELEASE npm/safe-buffer@5.2.1: Package last released 2115 days ago (5.8 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_REPO_ABANDONED Latest human commit: 2020-10-28
lodash @4.17.20 VULN_HISTORICAL_SEVERE
  • CVE-2021-41720 (GHSA-8p5q-j9m2-g8wr) 9.8 low
  • CVE-2019-10744 (GHSA-jf85-cpcp-j695) 9.1 CRITICAL from nvd@nist.gov
  • CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) 7.2 HIGH from nvd@nist.gov (Secondary: report@snyk.io: 7.2 HIGH)
  • CVE-2020-8203 (GHSA-p6mc-m468-83gw) 7.4 HIGH from nvd@nist.gov
LICENSE_MODIFIED
  • LICENSE: MIT - 677 extra characters: 'based on underscore.js, copyright jeremy ashkenas, documentcloud and investigative reporters and editors <https://underscorejs.org/> this software consists of voluntary contributions made by many indi...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/LICENSE)
  • vendor/firebug-lite/license.txt: BSD-Source-Code - 243 extra characters: 'software license agreement (bsd license) redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or othe...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
LICENSE_NOT_APPROVED BSD-Source-Code (vendor/firebug-lite/license.txt) (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
strip-ansi @7.1.0 VULN_HISTORICAL_SEVERE MAL-2025-46980 CRITICAL
PACKAGE_PAST_MALWARE
  • npm/strip-ansi - Mitigated malware (affected versions removed from registry): 1
  • npm/strip-ansi - MAL-2025-46980: Malicious code in strip-ansi (npm) (affected versions yanked: 7.1.1)
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
wrap-ansi @9.0.0 SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
VULN_HISTORICAL_SEVERE MAL-2025-46983 CRITICAL
PACKAGE_PAST_MALWARE
  • npm/wrap-ansi - Mitigated malware (affected versions removed from registry): 1
  • npm/wrap-ansi - MAL-2025-46983: Malicious code in wrap-ansi (npm) (affected versions yanked: 9.0.1)
lodash @4.17.23 VULN_HISTORICAL_SEVERE
  • CVE-2019-10744 (GHSA-jf85-cpcp-j695) 9.1 CRITICAL from nvd@nist.gov
  • CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) 7.2 HIGH from nvd@nist.gov (Secondary: report@snyk.io: 7.2 HIGH)
  • CVE-2020-8203 (GHSA-p6mc-m468-83gw) 7.4 HIGH from nvd@nist.gov
  • CVE-2021-41720 (GHSA-8p5q-j9m2-g8wr) 9.8 low
LICENSE_MODIFIED
  • LICENSE: MIT - 677 extra characters: 'based on underscore.js, copyright jeremy ashkenas, documentcloud and investigative reporters and editors <https://underscorejs.org/> this software consists of voluntary contributions made by many indi...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/LICENSE)
  • vendor/firebug-lite/license.txt: BSD-Source-Code - 243 extra characters: 'software license agreement (bsd license) redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or othe...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
LICENSE_NOT_APPROVED BSD-Source-Code (vendor/firebug-lite/license.txt) (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
setprototypeof @1.2.0 PACKAGE_STALE_RELEASE npm/setprototypeof@1.2.0: Package last released 2412 days ago (6.6 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_REPO_ABANDONED Latest human commit: 2019-08-13
vary @1.1.2 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
PACKAGE_UNRELEASED_CHANGES
  • npm/vary: Latest human commit (2025-07-23) is 2859 days ahead of last release (2017-09-24).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/vary@1.1.2: Package last released 3074 days ago (8.4 years)
side-channel @1.1.0 PACKAGE_UNRELEASED_CHANGES
  • npm/side-channel: Latest human commit (2026-01-13) is 398 days ahead of last release (2024-12-11).
  • Source code has new human commits not released to package registry.
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
gopd @1.2.0 PACKAGE_UNRELEASED_CHANGES
  • npm/gopd: Latest human commit (2026-01-13) is 405 days ahead of last release (2024-12-04).
  • Source code has new human commits not released to package registry.
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
proxy-addr @2.0.7 PACKAGE_UNRELEASED_CHANGES
  • npm/proxy-addr: Latest human commit (2025-07-23) is 1513 days ahead of last release (2021-06-01).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/proxy-addr@2.0.7: Package last released 1728 days ago (4.7 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
side-channel-weakmap @1.0.2 PACKAGE_UNRELEASED_CHANGES
  • npm/side-channel-weakmap: Latest human commit (2025-12-29) is 383 days ahead of last release (2024-12-11).
  • Source code has new human commits not released to package registry.
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
has-symbols @1.1.0 PACKAGE_UNRELEASED_CHANGES
  • npm/has-symbols: Latest human commit (2025-12-29) is 392 days ahead of last release (2024-12-02).
  • Source code has new human commits not released to package registry.
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
toidentifier @1.0.1 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
PACKAGE_STALE_RELEASE npm/toidentifier@1.0.1: Package last released 1562 days ago (4.3 years)
SOURCE_REPO_STALE Latest human commit: 2021-11-14
media-typer @0.3.0 PACKAGE_UNRELEASED_CHANGES
  • npm/media-typer: Latest human commit (2025-07-23) is 2281 days ahead of last release (2019-04-25).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/media-typer@1.1.0: Package last released 2498 days ago (6.8 years)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
safer-buffer @2.1.2 SOURCE_REPO_ABANDONED Latest human commit: 2020-07-13
PACKAGE_UNRELEASED_CHANGES
  • npm/safer-buffer: Latest human commit (2020-07-13) is 827 days ahead of last release (2018-04-08).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/safer-buffer@2.1.2: Package last released 2878 days ago (7.9 years)
get-proto @1.0.1 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
PACKAGE_UNRELEASED_CHANGES
  • npm/get-proto: Latest human commit (2026-01-13) is 375 days ahead of last release (2025-01-02).
  • Source code has new human commits not released to package registry.
side-channel-map @1.0.1 PACKAGE_UNRELEASED_CHANGES
  • npm/side-channel-map: Latest human commit (2025-12-29) is 383 days ahead of last release (2024-12-11).
  • Source code has new human commits not released to package registry.
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
is-number @6.0.0 SOURCE_REPO_ABANDONED Latest human commit: 2018-07-04
PACKAGE_STALE_RELEASE npm/is-number@7.0.0: Package last released 2793 days ago (7.7 years)
on-finished @2.4.1 PACKAGE_UNRELEASED_CHANGES
  • npm/on-finished: Latest human commit (2025-11-27) is 1373 days ahead of last release (2022-02-22).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/on-finished@2.4.1: Package last released 1462 days ago (4.0 years)
content-type @1.0.5 PACKAGE_UNRELEASED_CHANGES
  • npm/content-type: Latest human commit (2026-02-19) is 1116 days ahead of last release (2023-01-29).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/content-type@1.0.5: Package last released 1121 days ago (3.1 years)
math-intrinsics @1.1.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_STALE Latest human commit: 2024-12-18
debug @2.6.9 VULN_HISTORICAL_SEVERE
  • CVE-2025-59144 (GHSA-4x49-vf9v-38px) CRITICAL
  • CVE-2017-20165 (GHSA-9vvw-cc9w-f27h) 7.5 HIGH from nvd@nist.gov (Secondary: cna@vuldb.com: 3.5 LOW)
PACKAGE_PAST_MALWARE
  • npm/debug - Fixed malware advisories: 1
  • npm/debug - GHSA-4x49-vf9v-38px: debug@4.4.2 contains malware after npm account takeover (fixed in 4.4.3)
bytes @3.1.2 PACKAGE_STALE_RELEASE npm/bytes@3.1.2: Package last released 1487 days ago (4.1 years)
SOURCE_REPO_STALE Latest human commit: 2022-01-27
es-errors @1.3.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_STALE Latest human commit: 2024-03-08
es-object-atoms @1.1.1 SOURCE_REPO_STALE Latest human commit: 2025-01-14
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
parseurl @1.3.3 PACKAGE_UNRELEASED_CHANGES
  • npm/parseurl: Latest human commit (2025-07-23) is 2290 days ahead of last release (2019-04-16).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE npm/parseurl@1.3.3: Package last released 2505 days ago (6.9 years)
object-inspect @1.13.4 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
is-even @1.0.0 SOURCE_REPO_ABANDONED Latest human commit: 2018-03-30
PACKAGE_STALE_RELEASE npm/is-even@1.0.0: Package last released 3195 days ago (8.8 years)
is-buffer @1.1.6 SOURCE_REPO_ABANDONED Latest human commit: 2020-11-03
PACKAGE_STALE_RELEASE npm/is-buffer@2.0.5: Package last released 1939 days ago (5.3 years)
call-bound @1.0.4 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
get-intrinsic @1.3.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
is-odd @0.1.2 PACKAGE_STALE_RELEASE npm/is-odd@3.0.1: Package last released 2826 days ago (7.7 years)
SOURCE_REPO_ABANDONED Latest human commit: 2018-05-31
hasown @2.0.2 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_STALE Latest human commit: 2024-03-10
es-define-property @1.0.1 SOURCE_REPO_STALE Latest human commit: 2024-12-06
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
call-bind-apply-helpers @1.0.2 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_STALE Latest human commit: 2025-02-12
is-odd @3.0.1 SOURCE_REPO_ABANDONED Latest human commit: 2018-05-31
PACKAGE_STALE_RELEASE npm/is-odd@3.0.1: Package last released 2826 days ago (7.7 years)
side-channel-list @1.0.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_STALE Latest human commit: 2024-12-10
merge-descriptors @1.0.1 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_REPO_STALE Latest human commit: 2023-12-21
ansi-regex @6.1.0 VULN_HISTORICAL_SEVERE
  • CVE-2021-3807 (GHSA-93q8-gq69-wqmw) 7.5 HIGH from nvd@nist.gov
  • MAL-2025-46966 CRITICAL
PACKAGE_PAST_MALWARE
  • npm/ansi-regex - Mitigated malware (affected versions removed from registry): 1
  • npm/ansi-regex - MAL-2025-46966: Malicious code in ansi-regex (npm) (affected versions yanked: 6.2.1)
is-number @3.0.0 SOURCE_REPO_ABANDONED Latest human commit: 2018-07-04
PACKAGE_STALE_RELEASE npm/is-number@7.0.0: Package last released 2793 days ago (7.7 years)
dunder-proto @1.0.1 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_STALE Latest human commit: 2024-12-16
escalade @3.2.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
SOURCE_REPO_STALE Latest human commit: 2024-08-29
fresh @0.5.2 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
VULN_HISTORICAL_SEVERE CVE-2017-16119 (GHSA-9qj9-36jm-prpv) 7.5 HIGH from nvd@nist.gov
ansi-styles @6.2.1 VULN_HISTORICAL_SEVERE MAL-2025-46967 CRITICAL
PACKAGE_PAST_MALWARE
  • npm/ansi-styles - Mitigated malware (affected versions removed from registry): 1
  • npm/ansi-styles - MAL-2025-46967: Malicious code in ansi-styles (npm) (affected versions yanked: 6.2.2)
ms @2.0.0 VULN_HISTORICAL_SEVERE CVE-2015-8315 (GHSA-3fx5-fwvr-xrjg) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
date-fns @4.1.0 SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
yargs-parser @22.0.0 SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
function-bind @1.1.2 SOURCE_REPO_STALE Latest human commit: 2023-10-12
emoji-regex @10.4.0 SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
get-east-asian-width @1.3.0 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
qs @6.10.3 VULN_HISTORICAL_SEVERE
  • CVE-2022-24999 (GHSA-hrpp-h998-j3pp) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
  • CVE-2025-15284 (GHSA-6rw7-vpxm-498p) 7.5 HIGH
  • CVE-2014-10064 (GHSA-f9cm-p3w6-xvr3) 7.5 HIGH from nvd@nist.gov
  • CVE-2017-1000048 (GHSA-gqgv-6jq5-jjj9) 7.5 HIGH from nvd@nist.gov
cookie-signature @1.0.6 SOURCE_REPO_STALE Latest human commit: 2024-10-29
path-to-regexp @0.1.7 VULN_HISTORICAL_SEVERE
  • CVE-2024-45296 (GHSA-9wv6-86v2-598j) 7.5 HIGH
  • CVE-2024-52798 (GHSA-rhx6-c78j-4q9w) 7.5 HIGH
mime @1.6.0 VULN_HISTORICAL_SEVERE CVE-2017-16138 (GHSA-wrvr-8mpx-r7pp) 7.5 HIGH from nvd@nist.gov
content-disposition @0.5.4 SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
ms @2.1.3 VULN_HISTORICAL_SEVERE CVE-2015-8315 (GHSA-3fx5-fwvr-xrjg) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
encodeurl @1.0.2 PACKAGE_UNRELEASED_CHANGES
  • npm/encodeurl: Latest human commit (2025-08-18) is 507 days ahead of last release (2024-03-29).
  • Source code has new human commits not released to package registry.
body-parser @1.20.0 VULN_HISTORICAL_SEVERE CVE-2024-45590 (GHSA-qwcr-r2fm-qrc7) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
accepts @1.3.8 PACKAGE_UNRELEASED_CHANGES
  • npm/accepts: Latest human commit (2026-01-20) is 507 days ahead of last release (2024-08-31).
  • Source code has new human commits not released to package registry.
send @0.18.0 VULN_HISTORICAL_SEVERE CVE-2014-6394 (GHSA-xwg4-93c6-3h42) 7.5 HIGH from nvd@nist.gov
negotiator @0.6.3 VULN_HISTORICAL_SEVERE CVE-2016-10539 (GHSA-7mc5-chhp-fmc3) 7.5 HIGH from nvd@nist.gov

pypi 38 of 49 packages with findings

Package Check Detail
numpy PACKAGE_INSTALL_SCRIPTS artifact pypi/numpy: numpy-2.4.2/numpy/_core/src/common/pythoncapi-compat/tests/setup.py, numpy-2.4.2/numpy/_core/tests/examples/cython/setup.py, numpy-2.4.2/numpy/_core/tests/examples/limited_api/setup.py, numpy-2.4.2/tools/swig/test/setup.py, numpy-2.4.2/vendored-meson/meson/setup.py
PACKAGE_LICENSE_MISMATCH pypi/numpy: unsatisfied term: 0BSD
VULN_HISTORICAL_SEVERE
  • CVE-2017-12852 (GHSA-frgw-fgh6-9g52) 7.5 HIGH from nvd@nist.gov
  • CVE-2019-6446 (GHSA-9fq2-x9r6-wfmf) 9.8 CRITICAL from nvd@nist.gov
LICENSE_MODIFIED
  • numpy/linalg/lapack_lite/LICENSE.txt: BSD-3-Clause-Open-MPI - 53 extra characters: '$copyright$ additional copyrights may follow $header$' (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/linalg/lapack_lite/LICENSE.txt)
  • numpy/random/LICENSE.md: BSD-3-Clause - 2043 extra characters: '**this software is dual-licensed under the the university of illinois/ncsa open source license (ncsa) and the 3-clause bsd license** # ncsa open source license **copyright 2019 kevin sheppard. all rig...' (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/random/LICENSE.md)
  • numpy/random/src/mt19937/LICENSE.md: BSD-3-Clause - 1356 extra characters: '# mt19937 the rk_random and rk_seed functions algorithms and the original design of the mersenne twister rng: original algorithm for the implementation of rk_interval function from richard j. wagner's...' (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/random/src/mt19937/LICENSE.md)
  • numpy/random/src/pcg64/LICENSE.md: MIT - 43 extra characters: '# pcg64 pcg random number generation for c.' (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/random/src/pcg64/LICENSE.md)
  • numpy/random/src/sfc64/LICENSE.md: MIT - 140 extra characters: '# sfc64 adapted from a c++ implementation of chris doty-humphrey's sfc prng. https://gist.github.com/imneme/f1f7821f07cf76504a97f6537c818083' (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/random/src/sfc64/LICENSE.md)
LICENSE_NOT_APPROVED
  • unknown (numpy/ma/LICENSE) (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/ma/LICENSE)
  • unknown (LICENSE.txt) (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/LICENSE.txt)
  • BSD-3-Clause-Open-MPI (numpy/linalg/lapack_lite/LICENSE.txt) (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/linalg/lapack_lite/LICENSE.txt)
  • unknown (numpy/random/src/distributions/LICENSE.md) (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/random/src/distributions/LICENSE.md)
  • unknown (numpy/random/src/philox/LICENSE.md) (URL: https://raw.githubusercontent.com/numpy/numpy/41f3673b434158cffe85f727ff435988d35ab6f6/numpy/random/src/philox/LICENSE.md)
python-dateutil PACKAGE_INSTALL_SCRIPTS artifact pypi/python-dateutil: python-dateutil-2.9.0.post0/setup.py
PACKAGE_LICENSE_MISMATCH pypi/python-dateutil: Dual License not satisfied by any available license
PACKAGE_UNRELEASED_CHANGES
  • pypi/python-dateutil: Latest human commit (2025-07-28) is 513 days ahead of last release (2024-03-01).
  • Source code has new human commits not released to package registry.
LICENSE_MODIFIED LICENSE: BSD-3-Clause - 884 extra characters: 'licensed under the apache license, version 2.0 (the 'license'); you may not use this file except in compliance with the license. you may obtain a copy of the license at https://www.apache.org/licenses...' (URL: https://raw.githubusercontent.com/dateutil/dateutil/e081f6725fbb49cae6eedab7010f517e8490859b/LICENSE)
certifi VULN_HISTORICAL_SEVERE
  • CVE-2022-23491 (GHSA-43fp-rhv2-5gv8) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 6.8 MEDIUM)
  • CVE-2023-37920 (GHSA-xqr8-7jwr-rhp7) 9.8 CRITICAL from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
  • CVE-2024-39689 (GHSA-248v-346w-9cwc) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
LICENSE_NOT_APPROVED unknown (LICENSE) (URL: https://raw.githubusercontent.com/certifi/python-certifi/8571a4ba5205675107f9026d0008ad2d7a2778bf/LICENSE)
PACKAGE_LICENSE_MISMATCH pypi/certifi: MPL-2.0 not satisfied by any available license
PACKAGE_INSTALL_SCRIPTS artifact pypi/certifi: certifi-2026.2.25/setup.py
colorama PACKAGE_UNRELEASED_CHANGES
  • pypi/colorama: Latest human commit (2025-07-09) is 988 days ahead of last release (2022-10-25).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE pypi/colorama@0.4.6: Package last released 1219 days ago (3.3 years)
LICENSE_NOT_APPROVED unknown (LICENSE.txt) (URL: https://raw.githubusercontent.com/tartley/colorama/406153f134db6b5c5391f223be46f9e8a902e6b6/LICENSE.txt)
PACKAGE_LICENSE_MISMATCH pypi/colorama: OSI Approved :: BSD License not satisfied by any available license
certifi @2026.1.4 PACKAGE_INSTALL_SCRIPTS artifact pypi/certifi: certifi-2026.1.4/setup.py
VULN_HISTORICAL_SEVERE
  • CVE-2024-39689 (GHSA-248v-346w-9cwc) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
  • CVE-2022-23491 (GHSA-43fp-rhv2-5gv8) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 6.8 MEDIUM)
  • CVE-2023-37920 (GHSA-xqr8-7jwr-rhp7) 9.8 CRITICAL from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
LICENSE_NOT_APPROVED unknown (LICENSE) (URL: https://raw.githubusercontent.com/certifi/python-certifi/8571a4ba5205675107f9026d0008ad2d7a2778bf/LICENSE)
PACKAGE_LICENSE_MISMATCH pypi/certifi: MPL-2.0 not satisfied by any available license
requests VULN_HISTORICAL_SEVERE CVE-2018-18074 (GHSA-x84v-xcm2-53pg) 7.5 HIGH from nvd@nist.gov
LICENSE_NOT_APPROVED unknown (ext/LICENSE) (URL: https://raw.githubusercontent.com/psf/requests/4bd79e397304d46dfccd76f36c07f66c0295ff82/ext/LICENSE)
PACKAGE_INSTALL_SCRIPTS artifact pypi/requests: requests-2.32.5/setup.py
exceptiongroup @1.3.1 PACKAGE_LICENSE_MISMATCH pypi/exceptiongroup: MIT not satisfied by any available license
LICENSE_MODIFIED LICENSE: PSF-2.0 - 1175 extra characters: 'the mit license (mit) permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the 'software'), to deal in the software without...' (URL: https://raw.githubusercontent.com/agronholm/exceptiongroup/0c6cfbf677f6b50df17311cfdad01e9ff17310aa/LICENSE)
LICENSE_NOT_APPROVED PSF-2.0 (LICENSE) (URL: https://raw.githubusercontent.com/agronholm/exceptiongroup/0c6cfbf677f6b50df17311cfdad01e9ff17310aa/LICENSE)
requests @2.32.5 LICENSE_NOT_APPROVED unknown (ext/LICENSE) (URL: https://raw.githubusercontent.com/psf/requests/4bd79e397304d46dfccd76f36c07f66c0295ff82/ext/LICENSE)
PACKAGE_INSTALL_SCRIPTS artifact pypi/requests: requests-2.32.5/setup.py
VULN_HISTORICAL_SEVERE CVE-2018-18074 (GHSA-x84v-xcm2-53pg) 7.5 HIGH from nvd@nist.gov
exceptiongroup LICENSE_MODIFIED LICENSE: PSF-2.0 - 1175 extra characters: 'the mit license (mit) permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the 'software'), to deal in the software without...' (URL: https://raw.githubusercontent.com/agronholm/exceptiongroup/0c6cfbf677f6b50df17311cfdad01e9ff17310aa/LICENSE)
LICENSE_NOT_APPROVED PSF-2.0 (LICENSE) (URL: https://raw.githubusercontent.com/agronholm/exceptiongroup/0c6cfbf677f6b50df17311cfdad01e9ff17310aa/LICENSE)
PACKAGE_LICENSE_MISMATCH pypi/exceptiongroup: MIT not satisfied by any available license
typing-extensions @4.15.0 PACKAGE_LICENSE_MISMATCH pypi/typing-extensions: PSF-2.0 not satisfied by any available license
LICENSE_NOT_APPROVED unknown (LICENSE) (URL: https://raw.githubusercontent.com/python/typing_extensions/442d8484f845f8863643ef490d81b82ec91d7963/LICENSE)
packaging @26.0 LICENSE_NOT_APPROVED unknown (LICENSE) (URL: https://raw.githubusercontent.com/pypa/packaging/65ed5e92673aaabbfbeafa9b70463ba41bbae9db/LICENSE)
PACKAGE_LICENSE_MISMATCH pypi/packaging: no term in (Apache-2.0 OR BSD-2-Clause) satisfied by available licenses
colorama @0.4.6 LICENSE_NOT_APPROVED unknown (LICENSE.txt) (URL: https://raw.githubusercontent.com/tartley/colorama/406153f134db6b5c5391f223be46f9e8a902e6b6/LICENSE.txt)
PACKAGE_LICENSE_MISMATCH pypi/colorama: OSI Approved :: BSD License not satisfied by any available license
Werkzeug VULN_RECENT_FREQUENCY pypi/Werkzeug: Found 3 vulnerabilities published in the last 365 days
VULN_HISTORICAL_SEVERE
  • CVE-2023-46136 (GHSA-hrfv-mqp8-q5rw) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 8.0 HIGH)
  • CVE-2024-49767 (GHSA-q34m-jh98-gwm2) 7.5 HIGH from nvd@nist.gov
  • CVE-2019-14322 (GHSA-j544-7q9p-6xp8) 7.5 HIGH from nvd@nist.gov
  • CVE-2023-25577 (GHSA-xg9f-g7g7-2323) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
  • CVE-2022-29361 (PYSEC-2022-203) 9.8 CRITICAL from nvd@nist.gov
  • ... and 2 more
gitpython PACKAGE_INSTALL_SCRIPTS artifact pypi/gitpython: gitpython-3.1.46/setup.py
VULN_HISTORICAL_SEVERE
  • CVE-2023-40590 (GHSA-wfm5-v35h-vwf4) 7.8 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.8 HIGH)
  • CVE-2024-22190 (GHSA-2mqj-m65w-jghx) 7.8 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.8 HIGH)
  • CVE-2022-24439 (GHSA-hcpj-qp55-gfph) 9.8 CRITICAL from nvd@nist.gov (Secondary: report@snyk.io: 8.1 HIGH)
  • CVE-2023-40267 (GHSA-pr76-5cm5-w9cj) 9.8 CRITICAL from nvd@nist.gov
typing-extensions PACKAGE_LICENSE_MISMATCH pypi/typing-extensions: PSF-2.0 not satisfied by any available license
LICENSE_NOT_APPROVED unknown (LICENSE) (URL: https://raw.githubusercontent.com/python/typing_extensions/442d8484f845f8863643ef490d81b82ec91d7963/LICENSE)
pandas VULN_HISTORICAL_SEVERE CVE-2020-13091 (PYSEC-2020-73) 9.8 CRITICAL from nvd@nist.gov
PACKAGE_LICENSE_MISMATCH pypi/pandas: Package license identifier exceeds 100 characters
werkzeug VULN_HISTORICAL_SEVERE
  • CVE-2019-14806 (GHSA-gq9m-qvpx-68hc) 7.5 HIGH from nvd@nist.gov
  • CVE-2023-46136 (GHSA-hrfv-mqp8-q5rw) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 8.0 HIGH)
  • CVE-2019-14322 (GHSA-j544-7q9p-6xp8) 7.5 HIGH from nvd@nist.gov
  • CVE-2024-34069 (GHSA-2g68-c3qc-8985) 7.5 HIGH
  • CVE-2024-49767 (GHSA-q34m-jh98-gwm2) 7.5 HIGH from nvd@nist.gov
  • ... and 2 more
VULN_RECENT_FREQUENCY pypi/werkzeug: Found 3 vulnerabilities published in the last 365 days
gitdb LICENSE_MODIFIED LICENSE: BSD-3-Clause - 438 extra characters: 'additional licenses the files at gitdb/test/fixtures/packs/pack-11fdfa9e156ab73caae3b6da867192221f2089c2.idx and gitdb/test/fixtures/packs/pack-11fdfa9e156ab73caae3b6da867192221f2089c2.pack are licens...' (URL: https://raw.githubusercontent.com/gitpython-developers/gitdb/4c63ee6636a6a3370f58b05d0bd19fec2f16dd5a/LICENSE)
PACKAGE_INSTALL_SCRIPTS artifact pypi/gitdb: gitdb-4.0.12/setup.py
smmap PACKAGE_INSTALL_SCRIPTS artifact pypi/smmap: smmap-5.0.2/setup.py
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
six PACKAGE_UNRELEASED_CHANGES
  • pypi/six: Latest human commit (2026-02-22) is 445 days ahead of last release (2024-12-04).
  • Source code has new human commits not released to package registry.
PACKAGE_INSTALL_SCRIPTS artifact pypi/six: six-1.17.0/setup.py
packaging PACKAGE_LICENSE_MISMATCH pypi/packaging: no term in (Apache-2.0 OR BSD-2-Clause) satisfied by available licenses
LICENSE_NOT_APPROVED unknown (LICENSE) (URL: https://raw.githubusercontent.com/pypa/packaging/65ed5e92673aaabbfbeafa9b70463ba41bbae9db/LICENSE)
urllib3 @2.6.3 VULN_HISTORICAL_SEVERE
  • CVE-2021-33503 (GHSA-q2q7-5pp4-w6pg) 7.5 HIGH from nvd@nist.gov
  • CVE-2026-21441 (GHSA-38jv-5279-wg99) 7.5 HIGH from nvd@nist.gov
  • CVE-2020-7212 (GHSA-hmv2-79q8-fv6g) 7.5 HIGH from nvd@nist.gov
  • CVE-2019-11324 (GHSA-mh33-7rrq-662w) 7.5 HIGH from nvd@nist.gov
  • CVE-2018-20060 (GHSA-www2-v7xj-xrc6) 9.8 CRITICAL from nvd@nist.gov
  • ... and 3 more
VULN_RECENT_FREQUENCY pypi/urllib3: Found 5 vulnerabilities published in the last 365 days
urllib3 VULN_HISTORICAL_SEVERE
  • CVE-2026-21441 (GHSA-38jv-5279-wg99) 7.5 HIGH from nvd@nist.gov
  • CVE-2020-7212 (GHSA-hmv2-79q8-fv6g) 7.5 HIGH from nvd@nist.gov
  • CVE-2019-11324 (GHSA-mh33-7rrq-662w) 7.5 HIGH from nvd@nist.gov
  • CVE-2025-66471 (GHSA-2xpw-w6gg-jr37) 7.5 HIGH from nvd@nist.gov
  • CVE-2021-33503 (GHSA-q2q7-5pp4-w6pg) 7.5 HIGH from nvd@nist.gov
  • ... and 3 more
VULN_RECENT_FREQUENCY pypi/urllib3: Found 5 vulnerabilities published in the last 365 days
jinja2 VULN_HISTORICAL_SEVERE
  • CVE-2024-56201 (GHSA-gmj6-6f8f-6699) 8.8 HIGH from nvd@nist.gov
  • CVE-2016-10745 (GHSA-hj2j-77xm-mc5v) 8.6 HIGH from nvd@nist.gov
  • CVE-2024-56326 (GHSA-q2x7-8rv6-6q7h) 7.8 HIGH
  • CVE-2019-10906 (GHSA-462w-v97r-4m45) 8.6 HIGH from nvd@nist.gov
  • CVE-2025-27516 (GHSA-cpwx-vrp4-4pq7) 8.8 HIGH from nvd@nist.gov
idna VULN_HISTORICAL_SEVERE CVE-2024-3651 (GHSA-jjg7-2v4v-x38h) 7.5 HIGH from nvd@nist.gov
pytest LICENSE_MODIFIED doc/en/license.rst: MIT - 178 extra characters: 'distributed under the terms of the 'mit'_ license, pytest is free and open source software. .. code-block:: text .. _'mit': https://github.com/pytest-dev/pytest/blob/main/license' (URL: https://raw.githubusercontent.com/pytest-dev/pytest/9fd1eebd8af715b58832412bb8398d394ab67666/doc/en/license.rst)
charset-normalizer @3.4.4 PACKAGE_INSTALL_SCRIPTS artifact pypi/charset-normalizer: charset_normalizer-3.4.4/setup.py
charset_normalizer PACKAGE_INSTALL_SCRIPTS artifact pypi/charset_normalizer: charset_normalizer-3.4.4/setup.py
MarkupSafe PACKAGE_INSTALL_SCRIPTS artifact pypi/MarkupSafe: markupsafe-3.0.3/setup.py
idna @3.11 VULN_HISTORICAL_SEVERE CVE-2024-3651 (GHSA-jjg7-2v4v-x38h) 7.5 HIGH from nvd@nist.gov
itsdangerous PACKAGE_UNRELEASED_CHANGES
  • pypi/itsdangerous: Latest human commit (2025-06-14) is 423 days ahead of last release (2024-04-16).
  • Source code has new human commits not released to package registry.
markupsafe PACKAGE_INSTALL_SCRIPTS artifact pypi/markupsafe: markupsafe-3.0.3/setup.py
pygments VULN_HISTORICAL_SEVERE
  • CVE-2021-20270 (GHSA-9w8r-397f-prfh) 7.5 HIGH from nvd@nist.gov
  • CVE-2015-8557 (GHSA-fff8-4w9p-7v76) 9.0 CRITICAL from nvd@nist.gov
  • CVE-2021-27291 (GHSA-pq64-v7f5-gqh8) 7.5 HIGH from nvd@nist.gov
Jinja2 VULN_HISTORICAL_SEVERE
  • CVE-2019-10906 (GHSA-462w-v97r-4m45) 8.6 HIGH from nvd@nist.gov
  • CVE-2024-56201 (GHSA-gmj6-6f8f-6699) 8.8 HIGH from nvd@nist.gov
  • CVE-2016-10745 (GHSA-hj2j-77xm-mc5v) 8.6 HIGH from nvd@nist.gov
  • CVE-2025-27516 (GHSA-cpwx-vrp4-4pq7) 8.8 HIGH from nvd@nist.gov
  • CVE-2024-56326 (GHSA-q2x7-8rv6-6q7h) 7.8 HIGH
tzdata LICENSE_MODIFIED LICENSE: Apache-2.0 - 27 extra characters: 'apache software license 2.0' (URL: https://raw.githubusercontent.com/python/tzdata/98fa430db23193017082f4c53d6769ddde969466/LICENSE)
pytest @9.0.2 LICENSE_MODIFIED doc/en/license.rst: MIT - 178 extra characters: 'distributed under the terms of the 'mit'_ license, pytest is free and open source software. .. code-block:: text .. _'mit': https://github.com/pytest-dev/pytest/blob/main/license' (URL: https://raw.githubusercontent.com/pytest-dev/pytest/9fd1eebd8af715b58832412bb8398d394ab67666/doc/en/license.rst)
pygments @2.19.2 VULN_HISTORICAL_SEVERE
  • CVE-2021-20270 (GHSA-9w8r-397f-prfh) 7.5 HIGH from nvd@nist.gov
  • CVE-2015-8557 (GHSA-fff8-4w9p-7v76) 9.0 CRITICAL from nvd@nist.gov
  • CVE-2021-27291 (GHSA-pq64-v7f5-gqh8) 7.5 HIGH from nvd@nist.gov
flask VULN_HISTORICAL_SEVERE
  • CVE-2018-1000656 (GHSA-562c-5r94-xh97) 7.5 HIGH from nvd@nist.gov
  • CVE-2019-1010083 (GHSA-5wv5-4vpf-pj6m) 7.5 HIGH from nvd@nist.gov
  • CVE-2023-30861 (GHSA-m2qf-hxjv-5gpq) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)

rubygems 57 of 69 packages with findings

Package Check Detail
net-pop PACKAGE_LICENSE_MISMATCH rubygems/net-pop: unsatisfied term: Ruby
PACKAGE_UNRELEASED_CHANGES
  • rubygems/net-pop: Latest human commit (2025-11-25) is 1153 days ahead of last release (2022-09-28).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE rubygems/net-pop@0.1.2: Package last released 1246 days ago (3.4 years)
PACKAGE_DYNAMIC_NAME net-pop.gemspec: uses variable reference: name
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
websocket-extensions SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 2
VULN_HISTORICAL_SEVERE CVE-2020-7663 (GHSA-g6wq-qcwm-j5g2) 7.5 HIGH from nvd@nist.gov
PACKAGE_UNRELEASED_CHANGES
  • rubygems/websocket-extensions: Latest human commit (2023-09-07) is 1192 days ahead of last release (2020-06-02).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE rubygems/websocket-extensions@0.1.5: Package last released 2094 days ago (5.7 years)
SOURCE_REPO_STALE Latest human commit: 2023-09-07
nokogiri LICENSE_MODIFIED LICENSE-DEPENDENCIES.md: Apache-2.0 - 95724 extra characters: '# vendored dependency licenses nokogiri ships with some third party dependencies, which are listed here along with their licenses. note that this document is broken into multiple sections, each of whi...' (URL: https://raw.githubusercontent.com/sparklemotion/nokogiri/d8abbfd34a82717ba106be34446833415499f68f/LICENSE-DEPENDENCIES.md)
PACKAGE_INSTALL_SCRIPTS artifact rubygems/nokogiri: ext/nokogiri/extconf.rb
VULN_HISTORICAL_SEVERE
  • GHSA-mrxw-mxhj-p664 7.8 HIGH
  • CVE-2021-41098 (GHSA-2rr5-8q37-2w7h) 7.5 HIGH from nvd@nist.gov
  • CVE-2021-30560 (GHSA-59gp-qqm7-cw4j) 8.8 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 8.8 HIGH)
  • CVE-2019-18197 (GHSA-242x-7cm6-4w8j) 7.5 HIGH from nvd@nist.gov
  • CVE-2019-5477 (GHSA-cr5j-953j-xw5p) 9.8 CRITICAL from nvd@nist.gov
  • ... and 21 more
VULN_RECENT_FREQUENCY rubygems/nokogiri: Found 6 vulnerabilities published in the last 365 days
net-smtp LICENSE_NOT_APPROVED unknown (LICENSE.txt) (URL: https://raw.githubusercontent.com/ruby/net-smtp/01cb1a89ba92218ff97b07618945c4b1ee4f3123/LICENSE.txt)
PACKAGE_DYNAMIC_NAME net-smtp.gemspec: uses variable reference: name
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
crass PACKAGE_UNRELEASED_CHANGES
  • rubygems/crass: Latest human commit (2024-05-23) is 1592 days ahead of last release (2020-01-12).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE rubygems/crass@1.0.6: Package last released 2235 days ago (6.1 years)
SOURCE_REPO_STALE Latest human commit: 2024-05-23
tzinfo VULN_HISTORICAL_SEVERE CVE-2022-31163 (GHSA-5cm2-9h8c-rvfx) 8.1 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
PACKAGE_UNRELEASED_CHANGES
  • rubygems/tzinfo: Latest human commit (2025-12-30) is 995 days ahead of last release (2023-04-10).
  • Source code has new human commits not released to package registry.
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
prettyprint PACKAGE_LICENSE_MISMATCH rubygems/prettyprint: unsatisfied term: Ruby
PACKAGE_UNRELEASED_CHANGES
  • rubygems/prettyprint: Latest human commit (2026-02-11) is 827 days ahead of last release (2023-11-07).
  • Source code has new human commits not released to package registry.
PACKAGE_DYNAMIC_NAME prettyprint.gemspec: uses variable reference: name
bundler VULN_HISTORICAL_SEVERE
  • CVE-2021-43809 (GHSA-fj7f-vq84-fh43) 7.3 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 6.7 MEDIUM)
  • CVE-2020-36327 (GHSA-fp4w-jxhp-m23p) 8.8 HIGH from nvd@nist.gov
  • CVE-2019-3881 (GHSA-g98m-96g9-wfjq) 7.8 HIGH from nvd@nist.gov
  • CVE-2016-7954 (GHSA-jvgm-pfqv-887x) 9.8 CRITICAL from nvd@nist.gov
LICENSE_MODIFIED lib/rubygems/vendor/molinillo/LICENSE: MIT - 30 extra characters: 'this project is licensed under' (URL: https://raw.githubusercontent.com/ruby/rubygems/7c541a245c5f143fd3ba382647645b2fe396acd8/lib/rubygems/vendor/molinillo/LICENSE)
LICENSE_NOT_APPROVED unknown (LICENSE.txt) (URL: https://raw.githubusercontent.com/ruby/rubygems/7c541a245c5f143fd3ba382647645b2fe396acd8/LICENSE.txt)
rack VULN_HISTORICAL_SEVERE
  • CVE-2024-25126 (GHSA-22f2-v57c-j9cx) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 5.3 MEDIUM)
  • CVE-2025-27111 (GHSA-8cgq-6mh2-7j6v) 7.5 HIGH from nvd@nist.gov
  • CVE-2025-46727 (GHSA-gjh7-p2fx-99vx) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
  • CVE-2022-30123 (GHSA-wq4h-7r42-5hrr) 10.0 CRITICAL from nvd@nist.gov
  • CVE-2023-27530 (GHSA-3h57-hmj3-gj3p) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
  • ... and 16 more
VULN_RECENT_FREQUENCY rubygems/rack: Found 13 vulnerabilities published in the last 365 days
LICENSE_NOT_APPROVED unknown (contrib/LICENSE.md) (URL: https://raw.githubusercontent.com/rack/rack/75c5745c286637a8f049a33790c71237762069e7/contrib/LICENSE.md)
securerandom PACKAGE_DYNAMIC_NAME securerandom.gemspec: uses variable reference: name
PACKAGE_UNRELEASED_CHANGES
  • rubygems/securerandom: Latest human commit (2026-02-09) is 420 days ahead of last release (2024-12-16).
  • Source code has new human commits not released to package registry.
tsort PACKAGE_DYNAMIC_NAME tsort.gemspec: uses variable reference: name
PACKAGE_UNRELEASED_CHANGES
  • rubygems/tsort: Latest human commit (2026-02-10) is 825 days ahead of last release (2023-11-07).
  • Source code has new human commits not released to package registry.
net-imap LICENSE_NOT_APPROVED unknown (LICENSE.txt) (URL: https://raw.githubusercontent.com/ruby/net-imap/55b5f1ccb3186729bc3fbb959113755544892c3b/LICENSE.txt)
PACKAGE_DYNAMIC_NAME net-imap.gemspec: uses variable reference: name
rails-html-sanitizer VULN_HISTORICAL_SEVERE CVE-2022-23517 (GHSA-5x79-w82f-gw8w) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
LICENSE_MODIFIED MIT-LICENSE: MIT - 79 extra characters: 'copyright 2013-2023 rafael mendonça frança, kasper timm hansen, mike dalessio' (URL: https://raw.githubusercontent.com/rails/rails-html-sanitizer/a8a04134d77f765a166188ef0850369adb6686ab/MIT-LICENSE)
net-protocol PACKAGE_UNRELEASED_CHANGES
  • rubygems/net-protocol: Latest human commit (2026-02-09) is 825 days ahead of last release (2023-11-07).
  • Source code has new human commits not released to package registry.
PACKAGE_DYNAMIC_NAME net-protocol.gemspec: uses variable reference: name
activerecord VULN_HISTORICAL_SEVERE
  • CVE-2016-6317 (GHSA-pr3r-4wrp-r2pv) 7.5 HIGH from nvd@nist.gov
  • CVE-2022-44566 (GHSA-579w-22j4-4749) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
  • CVE-2012-2695 (GHSA-76wq-xw4h-f8wj) 7.5 HIGH from nvd@nist.gov
  • CVE-2011-0448 (GHSA-jmm9-2p29-vh2w) 7.5 HIGH from nvd@nist.gov
  • CVE-2014-3483 (GHSA-r8fh-hq2p-7qhq) 7.5 HIGH from nvd@nist.gov
  • ... and 9 more
LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
actionview VULN_HISTORICAL_SEVERE
  • CVE-2019-5418 (GHSA-86g5-2wh3-gc9j) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
  • CVE-2016-0752 (GHSA-xrr4-p6fq-hjg7) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
  • CVE-2020-8163 (GHSA-cr3x-7m39-c6jq) 8.8 HIGH from nvd@nist.gov
  • CVE-2019-5419 (GHSA-m63j-wh5w-c252) 7.5 HIGH from nvd@nist.gov
LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
puma PACKAGE_INSTALL_SCRIPTS artifact rubygems/puma: ext/puma_http11/extconf.rb
VULN_HISTORICAL_SEVERE
  • CVE-2023-40175 (GHSA-68xg-gqqm-vgj8) 9.8 CRITICAL from nvd@nist.gov (Secondary: security-advisories@github.com: 7.3 HIGH)
  • CVE-2024-21647 (GHSA-c2f4-cvqm-65w2) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 5.9 MEDIUM)
  • CVE-2022-24790 (GHSA-h99w-9q5r-gjq9) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 9.1 CRITICAL)
  • CVE-2020-11076 (GHSA-x7jg-6pwg-fx5h) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
  • CVE-2019-16770 (GHSA-7xx3-m584-x994) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 5.3 MEDIUM)
  • ... and 3 more
actionpack VULN_HISTORICAL_SEVERE
  • CVE-2016-0751 (GHSA-ffpv-c4hm-3x6v) 7.5 HIGH from nvd@nist.gov
  • CVE-2011-0449 (GHSA-4ww3-3rxj-8v6q) 7.5 HIGH from nvd@nist.gov
  • CVE-2014-0130 (GHSA-6x85-j5j2-27jx) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
  • CVE-2023-22795 (GHSA-8xww-x3g3-6jcv) 7.5 HIGH from nvd@nist.gov
  • CVE-2021-22885 (GHSA-hjg4-8q5f-x6fm) 7.5 HIGH from nvd@nist.gov
  • ... and 10 more
LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
bigdecimal PACKAGE_LICENSE_MISMATCH rubygems/bigdecimal: unsatisfied term: BSD-2-Clause
PACKAGE_DYNAMIC_NAME bigdecimal.gemspec: uses variable reference: name
nio4r PACKAGE_INSTALL_SCRIPTS artifact rubygems/nio4r: ext/nio4r/extconf.rb
LICENSE_MODIFIED
  • ext/libev/LICENSE: BSD-2-Clause - 789 extra characters: 'all files in libev are copyright2007, 2008, 2009, 2010, 2011, 2012, 2013 marc alexander lehmann. alternatively, the contents of this package may be used under the terms of the gnu general public licen...' (URL: https://raw.githubusercontent.com/socketry/nio4r/8d49449f3818cdfed9b46eb6587620fdebb6be6b/ext/libev/LICENSE)
  • license.md: MIT - 191 extra characters: '## libev released under the bsd-2-clause or gpl-2.0-or-later license. see [ext/libev/license] for details. [ext/libev/license]: https://github.com/socketry/nio4r/blob/master/ext/libev/license' (URL: https://raw.githubusercontent.com/socketry/nio4r/8d49449f3818cdfed9b46eb6587620fdebb6be6b/license.md)
erubi SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
PACKAGE_UNRELEASED_CHANGES
  • rubygems/erubi: Latest human commit (2025-12-21) is 367 days ahead of last release (2024-12-19).
  • Source code has new human commits not released to package registry.
mini_mime PACKAGE_UNRELEASED_CHANGES
  • rubygems/mini_mime: Latest human commit (2024-12-30) is 509 days ahead of last release (2023-08-08).
  • Source code has new human commits not released to package registry.
SOURCE_REPO_STALE Latest human commit: 2024-12-30
rails LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
VULN_HISTORICAL_SEVERE
  • CVE-2009-2422 (GHSA-rxq3-gm4p-5fj4) 9.8 CRITICAL from nvd@nist.gov
  • CVE-2006-4111 (GHSA-rvpq-5xqx-pfpp) 7.5 HIGH from nvd@nist.gov
  • CVE-2006-4112 (GHSA-9wrq-xvmp-xjc8) 7.5 HIGH from nvd@nist.gov
erb LICENSE_NOT_APPROVED unknown (LICENSE.txt) (URL: https://raw.githubusercontent.com/ruby/erb/3d4dc31905e978d46f1eeda7bacaa469ce543733/LICENSE.txt)
PACKAGE_INSTALL_SCRIPTS artifact rubygems/erb: ext/erb/escape/extconf.rb
activejob VULN_HISTORICAL_SEVERE CVE-2018-16476 (GHSA-q2qw-rmrh-vv42) 7.5 HIGH from nvd@nist.gov
LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
activesupport VULN_HISTORICAL_SEVERE
  • CVE-2013-0333 (GHSA-xgr2-v94m-rc9g) 7.5 HIGH from nvd@nist.gov
  • CVE-2020-8165 (GHSA-2p68-f74v-9wc6) 9.8 CRITICAL from nvd@nist.gov
  • CVE-2023-22796 (GHSA-j6gc-792m-qgm2) 7.5 HIGH from nvd@nist.gov
LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
activestorage VULN_HISTORICAL_SEVERE
  • CVE-2020-8162 (GHSA-m42x-37p3-fv5w) 7.5 HIGH from nvd@nist.gov
  • CVE-2025-24293 (GHSA-r4mg-4433-c7g3) 9.2 CRITICAL
  • CVE-2022-21831 (GHSA-w749-p3v6-hccq) 9.8 CRITICAL from nvd@nist.gov
LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
mail SOURCE_REPO_STALE Latest human commit: 2025-01-22
VULN_HISTORICAL_SEVERE CVE-2012-2140 (GHSA-rp63-jfmw-532w) 7.5 HIGH from nvd@nist.gov
railties VULN_HISTORICAL_SEVERE CVE-2019-5420 (GHSA-m42h-mh85-4qgc) 9.8 CRITICAL from nvd@nist.gov
LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
uri VULN_HISTORICAL_SEVERE CVE-2025-61594 (GHSA-j4pr-3wm6-xx2r) 7.5 HIGH from nvd@nist.gov
globalid VULN_HISTORICAL_SEVERE CVE-2023-22799 (GHSA-23c2-gwp5-pxw9) 7.5 HIGH from nvd@nist.gov
actiontext LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
builder SOURCE_REPO_STALE Latest human commit: 2024-06-06
jar-dependencies SOURCE_REPO_STALE Latest human commit: 2025-02-10
concurrent-ruby LICENSE_MODIFIED LICENSE.txt: MIT - 95 extra characters: 'copyright jerry d'antonio -- released under https://www.opensource.org/licenses/mit-license.php' (URL: https://raw.githubusercontent.com/ruby-concurrency/concurrent-ruby/30dc89e4c7b61833126d762a9d6cec8de937d35f/LICENSE.txt)
timeout PACKAGE_DYNAMIC_NAME timeout.gemspec: uses variable reference: name
actioncable LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
base64 PACKAGE_DYNAMIC_NAME base64.gemspec: uses variable reference: name
pp PACKAGE_DYNAMIC_NAME pp.gemspec: uses variable reference: name
actionmailer LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
activemodel LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
date VULN_HISTORICAL_SEVERE CVE-2021-41817 (GHSA-qg54-694p-wgpp) 7.5 HIGH from nvd@nist.gov
drb PACKAGE_LICENSE_MISMATCH rubygems/drb: unsatisfied term: Ruby
racc PACKAGE_UNRELEASED_CHANGES
  • rubygems/racc: Latest human commit (2026-02-10) is 559 days ahead of last release (2024-07-30).
  • Source code has new human commits not released to package registry.
io-console PACKAGE_INSTALL_SCRIPTS artifact rubygems/io-console: ext/io/console/extconf.rb
actionmailbox LICENSE_MODIFIED activerecord/MIT-LICENSE: MIT - 94 extra characters: 'arel originally copyright 2007-2016 nick kallen, bryan helmkamp, emilio tagua, aaron patterson' (URL: https://raw.githubusercontent.com/rails/rails/63cb9037938274358037e6bca13d22c0ccbf9fb8/activerecord/MIT-LICENSE)
rack-session SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1
json VULN_HISTORICAL_SEVERE
  • CVE-2013-0269 (GHSA-x457-cw4h-hq5f) 7.5 HIGH from nvd@nist.gov
  • CVE-2025-27788 (GHSA-9m3q-rhmv-5q44) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
  • CVE-2020-10663 (GHSA-jphg-qwrw-7w9g) 7.5 HIGH from nvd@nist.gov
psych PACKAGE_INSTALL_SCRIPTS artifact rubygems/psych: ext/psych/extconf.rb
irb PACKAGE_LICENSE_MISMATCH rubygems/irb: unsatisfied term: Ruby
rails-dom-testing LICENSE_MODIFIED MIT-LICENSE: MIT - 38 extra characters: 'copyright 2013-2015 kasper timm hansen' (URL: https://raw.githubusercontent.com/rails/rails-dom-testing/8285bf18eb8343ba5dc4ba17eb983640422cf394/MIT-LICENSE)
websocket-driver PACKAGE_INSTALL_SCRIPTS artifact rubygems/websocket-driver: ext/websocket-driver/extconf.rb
loofah VULN_HISTORICAL_SEVERE
  • CVE-2022-23516 (GHSA-3x8r-x6xp-q4vm) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
  • CVE-2022-23514 (GHSA-486f-hjj9-9vhh) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH)
useragent SOURCE_REPO_STALE Latest human commit: 2024-12-04
i18n VULN_HISTORICAL_SEVERE CVE-2014-10077 (GHSA-34hf-g744-jw64) 7.5 HIGH from nvd@nist.gov
prism PACKAGE_INSTALL_SCRIPTS artifact rubygems/prism: ext/prism/extconf.rb
thor VULN_HISTORICAL_SEVERE CVE-2025-54314 (GHSA-mqcp-p2hv-vw6x) 7.9 high

source 1 of 1 packages with findings

Package Check Detail
source/github.com/Risk-Guard/public-test?commit=62d520e515ce1e3b28470bd4b0579df04d054220&trusted=true SOURCE_UNSUPPORTED_MANIFEST_FILE
  • ecosystem/npm/package-lock.json (npm, OSV ecosystem: npm)
  • npm/package-lock.json (npm, OSV ecosystem: npm)
  • pipenv/Pipfile (pipenv, OSV ecosystem: PyPI)
  • pipenv/Pipfile.lock (pipenv, OSV ecosystem: PyPI)
  • pnpm/pnpm-lock.yaml (pnpm, OSV ecosystem: npm)
SOURCE_MANIFEST_WITHOUT_LOCKFILE
  • [pypi] requirements.txt
  • [rubygems] Gemfile
PACKAGE_SOURCE_URL_MISMATCH
  • npm/test: Registry reports source URL "https://github.com/nodejs/node-core-test" but analyzing repository "https://github.com/Risk-Guard/public-test"
  • rubygems/example: Registry reports source URL "https://github.com/robotarmy/example" but analyzing repository "https://github.com/Risk-Guard/public-test"
PACKAGE_UNRELEASED_CHANGES
  • npm/test: Latest human commit (2026-02-25) is 1113 days ahead of last release (2023-02-08).
  • Source code has new human commits not released to package registry.
  • rubygems/example: Latest human commit (2026-02-25) is 5457 days ahead of last release (2011-03-19).
  • Source code has new human commits not released to package registry.
PACKAGE_STALE_RELEASE
  • npm/test@3.3.0: Package last released 1113 days ago (3.0 years)
  • rubygems/example@1.0.2: Package last released 5457 days ago (15.0 years)
SOURCE_NO_LICENSE No license file found in source repository
PACKAGE_NO_LICENSE rubygems/example: Package does not declare a license
PACKAGE_REGISTRY_MISMATCH pypi/test: Package not found in public registry (https://pypi.org/project/test)
SOURCE_FEW_CONTRIBUTORS Peak monthly authors: 1
SOURCE_REPO_NEW First commit: 2025-04-21
SOURCE_SINGLE_CONTRIBUTOR Authors in last 365 days: 1