| inherits
@2.0.4 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| PACKAGE_LICENSE_MISMATCH | npm/inherits: ISC not satisfied by any available license |
| PACKAGE_UNRELEASED_CHANGES | - npm/inherits: Latest human commit (2025-10-25) is 2319 days ahead of last release (2019-06-19).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/inherits@2.0.4: Package last released 2441 days ago (6.7 years) |
| forwarded
@0.2.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| VULN_HISTORICAL_SEVERE | CVE-2017-16118 (GHSA-mpcf-4gmh-23w8) 7.5 HIGH from nvd@nist.gov |
| PACKAGE_UNRELEASED_CHANGES | - npm/forwarded: Latest human commit (2025-07-23) is 1513 days ahead of last release (2021-05-31).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/forwarded@0.2.0: Package last released 1728 days ago (4.7 years) |
| ee-first
@1.1.1 | PACKAGE_UNRELEASED_CHANGES | - npm/ee-first: Latest human commit (2018-06-05) is 1107 days ahead of last release (2015-05-25).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/ee-first@1.1.1: Package last released 3927 days ago (10.8 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_REPO_ABANDONED | Latest human commit: 2018-06-05 |
| escape-html
@1.0.3 | PACKAGE_UNRELEASED_CHANGES | - npm/escape-html: Latest human commit (2019-01-10) is 1227 days ahead of last release (2015-09-01).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/escape-html@1.0.3: Package last released 3828 days ago (10.5 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_REPO_ABANDONED | Latest human commit: 2019-01-10 |
| unpipe
@1.0.0 | PACKAGE_UNRELEASED_CHANGES | - npm/unpipe: Latest human commit (2018-06-28) is 1110 days ahead of last release (2015-06-14).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/unpipe@1.0.0: Package last released 3907 days ago (10.7 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_ABANDONED | Latest human commit: 2018-06-28 |
| y18n
@5.0.8 | VULN_HISTORICAL_SEVERE | CVE-2020-7774 (GHSA-c4w7-xm78-47vh) 9.8 CRITICAL from nvd@nist.gov (Secondary: report@snyk.io: 7.3 HIGH) |
| PACKAGE_UNRELEASED_CHANGES | - npm/y18n: Latest human commit (2022-11-11) is 583 days ahead of last release (2021-04-07).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/y18n@5.0.8: Package last released 1783 days ago (4.9 years) |
| SOURCE_REPO_STALE | Latest human commit: 2022-11-11 |
| utils-merge
@1.0.1 | PACKAGE_UNRELEASED_CHANGES | - npm/utils-merge: Latest human commit (2020-06-16) is 1000 days ahead of last release (2017-09-20).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/utils-merge@1.0.1: Package last released 3080 days ago (8.4 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_ABANDONED | Latest human commit: 2020-06-16 |
| depd
@2.0.0 | PACKAGE_UNRELEASED_CHANGES | - npm/depd: Latest human commit (2021-11-12) is 1112 days ahead of last release (2018-10-26).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/depd@2.0.0: Package last released 2677 days ago (7.3 years) |
| SOURCE_REPO_STALE | Latest human commit: 2021-11-12 |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| array-flatten
@1.1.1 | PACKAGE_UNRELEASED_CHANGES | - npm/array-flatten: Latest human commit (2023-12-07) is 1477 days ahead of last release (2019-11-21).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/array-flatten@3.0.0: Package last released 2288 days ago (6.3 years) |
| SOURCE_REPO_STALE | Latest human commit: 2023-12-07 |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| methods
@1.1.2 | PACKAGE_STALE_RELEASE | npm/methods@1.1.2: Package last released 3691 days ago (10.1 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| PACKAGE_UNRELEASED_CHANGES | - npm/methods: Latest human commit (2025-06-05) is 3426 days ahead of last release (2016-01-18).
- Source code has new human commits not released to package registry.
|
| kind-of
@3.2.2 | SOURCE_REPO_STALE | Latest human commit: 2023-11-02 |
| VULN_HISTORICAL_SEVERE | CVE-2019-20149 (GHSA-6c8f-qphg-qjgp) 7.5 HIGH from nvd@nist.gov |
| PACKAGE_UNRELEASED_CHANGES | - npm/kind-of: Latest human commit (2023-11-02) is 1386 days ahead of last release (2020-01-16).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/kind-of@6.0.3: Package last released 2232 days ago (6.1 years) |
| range-parser
@1.2.1 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| PACKAGE_UNRELEASED_CHANGES | - npm/range-parser: Latest human commit (2026-01-23) is 2449 days ahead of last release (2019-05-11).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/range-parser@1.2.1: Package last released 2480 days ago (6.8 years) |
| lodash | VULN_HISTORICAL_SEVERE | - CVE-2020-8203 (GHSA-p6mc-m468-83gw) 7.4 HIGH from nvd@nist.gov
- CVE-2021-41720 (GHSA-8p5q-j9m2-g8wr) 9.8 low
- CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) 7.2 HIGH from nvd@nist.gov (Secondary: report@snyk.io: 7.2 HIGH)
- CVE-2019-10744 (GHSA-jf85-cpcp-j695) 9.1 CRITICAL from nvd@nist.gov
|
| LICENSE_MODIFIED | - LICENSE: MIT - 677 extra characters: 'based on underscore.js, copyright jeremy ashkenas, documentcloud and investigative reporters and editors <https://underscorejs.org/>
this software consists of voluntary contributions made by many indi...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/LICENSE)
- vendor/firebug-lite/license.txt: BSD-Source-Code - 243 extra characters: 'software license agreement (bsd license)
redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or othe...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
|
| LICENSE_NOT_APPROVED | BSD-Source-Code (vendor/firebug-lite/license.txt) (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt) |
| get-caller-file
@2.0.5 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_REPO_ABANDONED | Latest human commit: 2019-03-09 |
| PACKAGE_STALE_RELEASE | npm/get-caller-file@2.0.5: Package last released 2543 days ago (7.0 years) |
| destroy
@1.2.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| PACKAGE_STALE_RELEASE | npm/destroy@1.2.0: Package last released 1437 days ago (3.9 years) |
| SOURCE_REPO_STALE | Latest human commit: 2022-03-20 |
| etag
@1.8.1 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| PACKAGE_UNRELEASED_CHANGES | - npm/etag: Latest human commit (2025-07-23) is 2870 days ahead of last release (2017-09-13).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/etag@1.8.1: Package last released 3085 days ago (8.5 years) |
| safe-buffer
@5.2.1 | PACKAGE_STALE_RELEASE | npm/safe-buffer@5.2.1: Package last released 2115 days ago (5.8 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_REPO_ABANDONED | Latest human commit: 2020-10-28 |
| lodash
@4.17.20 | VULN_HISTORICAL_SEVERE | - CVE-2021-41720 (GHSA-8p5q-j9m2-g8wr) 9.8 low
- CVE-2019-10744 (GHSA-jf85-cpcp-j695) 9.1 CRITICAL from nvd@nist.gov
- CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) 7.2 HIGH from nvd@nist.gov (Secondary: report@snyk.io: 7.2 HIGH)
- CVE-2020-8203 (GHSA-p6mc-m468-83gw) 7.4 HIGH from nvd@nist.gov
|
| LICENSE_MODIFIED | - LICENSE: MIT - 677 extra characters: 'based on underscore.js, copyright jeremy ashkenas, documentcloud and investigative reporters and editors <https://underscorejs.org/>
this software consists of voluntary contributions made by many indi...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/LICENSE)
- vendor/firebug-lite/license.txt: BSD-Source-Code - 243 extra characters: 'software license agreement (bsd license)
redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or othe...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
|
| LICENSE_NOT_APPROVED | BSD-Source-Code (vendor/firebug-lite/license.txt) (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt) |
| strip-ansi
@7.1.0 | VULN_HISTORICAL_SEVERE | MAL-2025-46980 CRITICAL |
| PACKAGE_PAST_MALWARE | - npm/strip-ansi - Mitigated malware (affected versions removed from registry): 1
- npm/strip-ansi - MAL-2025-46980: Malicious code in strip-ansi (npm) (affected versions yanked: 7.1.1)
|
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| wrap-ansi
@9.0.0 | SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| VULN_HISTORICAL_SEVERE | MAL-2025-46983 CRITICAL |
| PACKAGE_PAST_MALWARE | - npm/wrap-ansi - Mitigated malware (affected versions removed from registry): 1
- npm/wrap-ansi - MAL-2025-46983: Malicious code in wrap-ansi (npm) (affected versions yanked: 9.0.1)
|
| lodash
@4.17.23 | VULN_HISTORICAL_SEVERE | - CVE-2019-10744 (GHSA-jf85-cpcp-j695) 9.1 CRITICAL from nvd@nist.gov
- CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) 7.2 HIGH from nvd@nist.gov (Secondary: report@snyk.io: 7.2 HIGH)
- CVE-2020-8203 (GHSA-p6mc-m468-83gw) 7.4 HIGH from nvd@nist.gov
- CVE-2021-41720 (GHSA-8p5q-j9m2-g8wr) 9.8 low
|
| LICENSE_MODIFIED | - LICENSE: MIT - 677 extra characters: 'based on underscore.js, copyright jeremy ashkenas, documentcloud and investigative reporters and editors <https://underscorejs.org/>
this software consists of voluntary contributions made by many indi...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/LICENSE)
- vendor/firebug-lite/license.txt: BSD-Source-Code - 243 extra characters: 'software license agreement (bsd license)
redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or othe...' (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt)
|
| LICENSE_NOT_APPROVED | BSD-Source-Code (vendor/firebug-lite/license.txt) (URL: https://raw.githubusercontent.com/lodash/lodash/07831814702e3ade48311fdb78d86b9ce3778f65/vendor/firebug-lite/license.txt) |
| setprototypeof
@1.2.0 | PACKAGE_STALE_RELEASE | npm/setprototypeof@1.2.0: Package last released 2412 days ago (6.6 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_REPO_ABANDONED | Latest human commit: 2019-08-13 |
| vary
@1.1.2 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| PACKAGE_UNRELEASED_CHANGES | - npm/vary: Latest human commit (2025-07-23) is 2859 days ahead of last release (2017-09-24).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/vary@1.1.2: Package last released 3074 days ago (8.4 years) |
| side-channel
@1.1.0 | PACKAGE_UNRELEASED_CHANGES | - npm/side-channel: Latest human commit (2026-01-13) is 398 days ahead of last release (2024-12-11).
- Source code has new human commits not released to package registry.
|
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| gopd
@1.2.0 | PACKAGE_UNRELEASED_CHANGES | - npm/gopd: Latest human commit (2026-01-13) is 405 days ahead of last release (2024-12-04).
- Source code has new human commits not released to package registry.
|
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| proxy-addr
@2.0.7 | PACKAGE_UNRELEASED_CHANGES | - npm/proxy-addr: Latest human commit (2025-07-23) is 1513 days ahead of last release (2021-06-01).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/proxy-addr@2.0.7: Package last released 1728 days ago (4.7 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| side-channel-weakmap
@1.0.2 | PACKAGE_UNRELEASED_CHANGES | - npm/side-channel-weakmap: Latest human commit (2025-12-29) is 383 days ahead of last release (2024-12-11).
- Source code has new human commits not released to package registry.
|
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| has-symbols
@1.1.0 | PACKAGE_UNRELEASED_CHANGES | - npm/has-symbols: Latest human commit (2025-12-29) is 392 days ahead of last release (2024-12-02).
- Source code has new human commits not released to package registry.
|
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| toidentifier
@1.0.1 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| PACKAGE_STALE_RELEASE | npm/toidentifier@1.0.1: Package last released 1562 days ago (4.3 years) |
| SOURCE_REPO_STALE | Latest human commit: 2021-11-14 |
| media-typer
@0.3.0 | PACKAGE_UNRELEASED_CHANGES | - npm/media-typer: Latest human commit (2025-07-23) is 2281 days ahead of last release (2019-04-25).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/media-typer@1.1.0: Package last released 2498 days ago (6.8 years) |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| safer-buffer
@2.1.2 | SOURCE_REPO_ABANDONED | Latest human commit: 2020-07-13 |
| PACKAGE_UNRELEASED_CHANGES | - npm/safer-buffer: Latest human commit (2020-07-13) is 827 days ahead of last release (2018-04-08).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/safer-buffer@2.1.2: Package last released 2878 days ago (7.9 years) |
| get-proto
@1.0.1 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| PACKAGE_UNRELEASED_CHANGES | - npm/get-proto: Latest human commit (2026-01-13) is 375 days ahead of last release (2025-01-02).
- Source code has new human commits not released to package registry.
|
| side-channel-map
@1.0.1 | PACKAGE_UNRELEASED_CHANGES | - npm/side-channel-map: Latest human commit (2025-12-29) is 383 days ahead of last release (2024-12-11).
- Source code has new human commits not released to package registry.
|
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| is-number
@6.0.0 | SOURCE_REPO_ABANDONED | Latest human commit: 2018-07-04 |
| PACKAGE_STALE_RELEASE | npm/is-number@7.0.0: Package last released 2793 days ago (7.7 years) |
| on-finished
@2.4.1 | PACKAGE_UNRELEASED_CHANGES | - npm/on-finished: Latest human commit (2025-11-27) is 1373 days ahead of last release (2022-02-22).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/on-finished@2.4.1: Package last released 1462 days ago (4.0 years) |
| content-type
@1.0.5 | PACKAGE_UNRELEASED_CHANGES | - npm/content-type: Latest human commit (2026-02-19) is 1116 days ahead of last release (2023-01-29).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/content-type@1.0.5: Package last released 1121 days ago (3.1 years) |
| math-intrinsics
@1.1.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_STALE | Latest human commit: 2024-12-18 |
| debug
@2.6.9 | VULN_HISTORICAL_SEVERE | - CVE-2025-59144 (GHSA-4x49-vf9v-38px) CRITICAL
- CVE-2017-20165 (GHSA-9vvw-cc9w-f27h) 7.5 HIGH from nvd@nist.gov (Secondary: cna@vuldb.com: 3.5 LOW)
|
| PACKAGE_PAST_MALWARE | - npm/debug - Fixed malware advisories: 1
- npm/debug - GHSA-4x49-vf9v-38px: debug@4.4.2 contains malware after npm account takeover (fixed in 4.4.3)
|
| bytes
@3.1.2 | PACKAGE_STALE_RELEASE | npm/bytes@3.1.2: Package last released 1487 days ago (4.1 years) |
| SOURCE_REPO_STALE | Latest human commit: 2022-01-27 |
| es-errors
@1.3.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_STALE | Latest human commit: 2024-03-08 |
| es-object-atoms
@1.1.1 | SOURCE_REPO_STALE | Latest human commit: 2025-01-14 |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| parseurl
@1.3.3 | PACKAGE_UNRELEASED_CHANGES | - npm/parseurl: Latest human commit (2025-07-23) is 2290 days ahead of last release (2019-04-16).
- Source code has new human commits not released to package registry.
|
| PACKAGE_STALE_RELEASE | npm/parseurl@1.3.3: Package last released 2505 days ago (6.9 years) |
| object-inspect
@1.13.4 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| is-even
@1.0.0 | SOURCE_REPO_ABANDONED | Latest human commit: 2018-03-30 |
| PACKAGE_STALE_RELEASE | npm/is-even@1.0.0: Package last released 3195 days ago (8.8 years) |
| is-buffer
@1.1.6 | SOURCE_REPO_ABANDONED | Latest human commit: 2020-11-03 |
| PACKAGE_STALE_RELEASE | npm/is-buffer@2.0.5: Package last released 1939 days ago (5.3 years) |
| call-bound
@1.0.4 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| get-intrinsic
@1.3.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| is-odd
@0.1.2 | PACKAGE_STALE_RELEASE | npm/is-odd@3.0.1: Package last released 2826 days ago (7.7 years) |
| SOURCE_REPO_ABANDONED | Latest human commit: 2018-05-31 |
| hasown
@2.0.2 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_STALE | Latest human commit: 2024-03-10 |
| es-define-property
@1.0.1 | SOURCE_REPO_STALE | Latest human commit: 2024-12-06 |
| SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| call-bind-apply-helpers
@1.0.2 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_STALE | Latest human commit: 2025-02-12 |
| is-odd
@3.0.1 | SOURCE_REPO_ABANDONED | Latest human commit: 2018-05-31 |
| PACKAGE_STALE_RELEASE | npm/is-odd@3.0.1: Package last released 2826 days ago (7.7 years) |
| side-channel-list
@1.0.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_STALE | Latest human commit: 2024-12-10 |
| merge-descriptors
@1.0.1 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_REPO_STALE | Latest human commit: 2023-12-21 |
| ansi-regex
@6.1.0 | VULN_HISTORICAL_SEVERE | - CVE-2021-3807 (GHSA-93q8-gq69-wqmw) 7.5 HIGH from nvd@nist.gov
- MAL-2025-46966 CRITICAL
|
| PACKAGE_PAST_MALWARE | - npm/ansi-regex - Mitigated malware (affected versions removed from registry): 1
- npm/ansi-regex - MAL-2025-46966: Malicious code in ansi-regex (npm) (affected versions yanked: 6.2.1)
|
| is-number
@3.0.0 | SOURCE_REPO_ABANDONED | Latest human commit: 2018-07-04 |
| PACKAGE_STALE_RELEASE | npm/is-number@7.0.0: Package last released 2793 days ago (7.7 years) |
| dunder-proto
@1.0.1 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 1 |
| SOURCE_REPO_STALE | Latest human commit: 2024-12-16 |
| escalade
@3.2.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| SOURCE_REPO_STALE | Latest human commit: 2024-08-29 |
| fresh
@0.5.2 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| VULN_HISTORICAL_SEVERE | CVE-2017-16119 (GHSA-9qj9-36jm-prpv) 7.5 HIGH from nvd@nist.gov |
| ansi-styles
@6.2.1 | VULN_HISTORICAL_SEVERE | MAL-2025-46967 CRITICAL |
| PACKAGE_PAST_MALWARE | - npm/ansi-styles - Mitigated malware (affected versions removed from registry): 1
- npm/ansi-styles - MAL-2025-46967: Malicious code in ansi-styles (npm) (affected versions yanked: 6.2.2)
|
| ms
@2.0.0 | VULN_HISTORICAL_SEVERE | CVE-2015-8315 (GHSA-3fx5-fwvr-xrjg) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH) |
| date-fns
@4.1.0 | SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| yargs-parser
@22.0.0 | SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| function-bind
@1.1.2 | SOURCE_REPO_STALE | Latest human commit: 2023-10-12 |
| emoji-regex
@10.4.0 | SOURCE_SINGLE_CONTRIBUTOR | Authors in last 365 days: 1 |
| get-east-asian-width
@1.3.0 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| qs
@6.10.3 | VULN_HISTORICAL_SEVERE | - CVE-2022-24999 (GHSA-hrpp-h998-j3pp) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH)
- CVE-2025-15284 (GHSA-6rw7-vpxm-498p) 7.5 HIGH
- CVE-2014-10064 (GHSA-f9cm-p3w6-xvr3) 7.5 HIGH from nvd@nist.gov
- CVE-2017-1000048 (GHSA-gqgv-6jq5-jjj9) 7.5 HIGH from nvd@nist.gov
|
| cookie-signature
@1.0.6 | SOURCE_REPO_STALE | Latest human commit: 2024-10-29 |
| path-to-regexp
@0.1.7 | VULN_HISTORICAL_SEVERE | - CVE-2024-45296 (GHSA-9wv6-86v2-598j) 7.5 HIGH
- CVE-2024-52798 (GHSA-rhx6-c78j-4q9w) 7.5 HIGH
|
| mime
@1.6.0 | VULN_HISTORICAL_SEVERE | CVE-2017-16138 (GHSA-wrvr-8mpx-r7pp) 7.5 HIGH from nvd@nist.gov |
| content-disposition
@0.5.4 | SOURCE_FEW_CONTRIBUTORS | Peak monthly authors: 2 |
| ms
@2.1.3 | VULN_HISTORICAL_SEVERE | CVE-2015-8315 (GHSA-3fx5-fwvr-xrjg) 7.5 HIGH from nvd@nist.gov (Secondary: 134c704f-9b21-4f2e-91b3-4a467353bcc0: 7.5 HIGH) |
| encodeurl
@1.0.2 | PACKAGE_UNRELEASED_CHANGES | - npm/encodeurl: Latest human commit (2025-08-18) is 507 days ahead of last release (2024-03-29).
- Source code has new human commits not released to package registry.
|
| body-parser
@1.20.0 | VULN_HISTORICAL_SEVERE | CVE-2024-45590 (GHSA-qwcr-r2fm-qrc7) 7.5 HIGH from nvd@nist.gov (Secondary: security-advisories@github.com: 7.5 HIGH) |
| accepts
@1.3.8 | PACKAGE_UNRELEASED_CHANGES | - npm/accepts: Latest human commit (2026-01-20) is 507 days ahead of last release (2024-08-31).
- Source code has new human commits not released to package registry.
|
| send
@0.18.0 | VULN_HISTORICAL_SEVERE | CVE-2014-6394 (GHSA-xwg4-93c6-3h42) 7.5 HIGH from nvd@nist.gov |
| negotiator
@0.6.3 | VULN_HISTORICAL_SEVERE | CVE-2016-10539 (GHSA-7mc5-chhp-fmc3) 7.5 HIGH from nvd@nist.gov |