Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 21, 2024 via pnpm

aframe 0.5.0

A web framework for building virtual reality experiences.
Package summary
Share
78
issues
11
critical severity
vulnerability
3
license
8
44
high severity
vulnerability
15
license
10
meta
19
9
moderate severity
vulnerability
9
14
low severity
vulnerability
4
license
10
14
licenses
388
MIT
40
ISC
13
BSD-3-Clause
37
other licenses
N/A
8
BSD-2-Clause
8
BSD
8
Apache-2.0
6
+ 7 more
Package created
7 Oct 2015
Version published
10 Feb 2017
Maintainers
5
Total deps
478
Direct deps
12
License
MIT

Issues

78

11 critical severity issues

critical
Recommendation: Upgrade to version 2.4.24 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 4.17.12 or later
via: browserify-css@0.8.4 & others
Recommendation: Upgrade to version 1.2.6 or later
via: tween.js@15.0.0
Recommendation: Check the package code and files for license information
via: browserify-css@0.8.4
Recommendation: Check the package code and files for license information
via: browserify-css@0.8.4
Recommendation: Check the package code and files for license information
via: browserify-css@0.8.4
Recommendation: Check the package code and files for license information
via: tween.js@15.0.0
Recommendation: Check the package code and files for license information
via: tween.js@15.0.0
Recommendation: Check the package code and files for license information
via: tween.js@15.0.0
Recommendation: Check the package code and files for license information
via: tween.js@15.0.0
Recommendation: Check the package code and files for license information
via: tween.js@15.0.0
Collapse
Expand

44 high severity issues

high
Recommendation: Upgrade to version 2.6.0 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 0.125.0 or later
via: three@0.83.0
Recommendation: Upgrade to version 3.0.2 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 4.2.1 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 4.17.11 or later
via: browserify-css@0.8.4 & others
Recommendation: Upgrade to version 5.1.2 or later
via: browserify-css@0.8.4
Recommendation: Upgrade to version 3.5.0 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 3.13.1 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 9.0.1 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 4.17.19 or later
via: tween.js@15.0.0
Recommendation: None
via: tween.js@15.0.0
Recommendation: Upgrade to version 2.1.1 or later
via: browserify-css@0.8.4
Recommendation: Upgrade to version 3.0.5 or later
via: tween.js@15.0.0
Recommendation: None
via: tween.js@15.0.0
Recommendation: Upgrade to version 4.17.21 or later
via: browserify-css@0.8.4 & others
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
Recommendation: Validate that the package complies with your license policy
via: envify@3.4.1
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
Recommendation: Validate that the package complies with your license policy
via: browserify-css@0.8.4 & others
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
Recommendation: Validate that the package complies with your license policy
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
via: tween.js@15.0.0
Collapse
Expand

9 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: browserify-css@0.8.4 & others
Recommendation: Upgrade to version 3.13.0 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 0.6.0 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 4.17.21 or later
via: browserify-css@0.8.4 & others
Recommendation: Upgrade to version 1.2.3 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 5.7.2 or later
via: tween.js@15.0.0
Recommendation: Upgrade to version 4.1.3 or later
via: tween.js@15.0.0
Recommendation: None
via: tween.js@15.0.0
Recommendation: Upgrade to version 3.7.1 or later
via: load-bmfont@1.4.1
Collapse
Expand

14 low severity issues

low
Recommendation: Upgrade to version 2.3.1 or later
via: browserify-css@0.8.4
Recommendation: Upgrade to version 4.17.5 or later
via: browserify-css@0.8.4 & others
Recommendation: Upgrade to version 2.3.1 or later
via: browserify-css@0.8.4
Recommendation: Upgrade to version 4.1.11 or later
via: browserify-css@0.8.4
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Recommendation: Read and validate the license terms
via: envify@3.4.1
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Recommendation: Read and validate the license terms
via: browserify-css@0.8.4 & others
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Recommendation: Read and validate the license terms
via: tween.js@15.0.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
388 Packages, Including:
acorn@5.7.4
aframe@0.5.0
an-array@1.0.0
ansi-gray@0.1.1
ansi-regex@2.1.1
ansi-styles@2.2.1
ansi-wrap@0.1.0
archy@1.0.0
argparse@1.0.10
arr-diff@2.0.0
arr-diff@4.0.0
arr-flatten@1.1.0
arr-union@3.1.0
array-differ@1.0.0
array-each@1.0.1
array-shuffle@1.0.1
array-slice@1.1.0
array-uniq@1.0.3
array-unique@0.2.1
array-unique@0.3.2
as-number@1.0.0
asn1@0.2.6
assert-plus@0.2.0
assert-plus@1.0.0
assign-symbols@1.0.0
ast-types@0.9.6
async@0.2.10
asynckit@0.4.0
aws4@1.12.0
balanced-match@1.0.2
base62@1.2.8
base@0.11.2
beeper@1.1.1
bl@1.2.3
bluebird@3.7.2
brace-expansion@1.1.11
braces@1.8.5
braces@2.3.2
browserify-css@0.8.4
buffer-equal@0.0.1
buffer-to-arraybuffer@0.0.5
cache-base@1.0.1
chalk@1.1.3
class-utils@0.3.6
clean-css@2.2.23
clean-yaml-object@0.1.0
cli@1.0.1
clone-buffer@1.0.0
clone-stats@0.0.1
clone-stats@1.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
40 Packages, Including:
color-support@1.1.3
concat-with-sourcemaps@1.1.0
events-to-array@1.1.2
foreground-child@1.5.6
fs.realpath@1.0.0
glob-parent@2.0.0
glob@4.5.3
glob@5.0.15
glob@7.2.3
graceful-fs@3.0.12
graceful-fs@4.2.11
har-validator@2.0.6
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
isexe@1.1.2
isexe@2.0.0
json-stringify-safe@5.0.1
lru-cache@2.7.3
lru-cache@4.1.5
minimatch@2.0.10
minimatch@3.0.8
minimatch@3.1.2
natives@1.1.6
nyc@7.1.0
once@1.3.3
once@1.4.0
only-shallow@1.2.0
pseudomap@1.0.2
remove-trailing-separator@1.1.0
sax@1.3.0
semver@4.3.6
sigmund@1.0.1
signal-exit@3.0.7
tap-mocha-reporter@2.0.1
tap@7.1.2
tmatch@2.0.1
which@1.3.1
wrappy@1.0.2
yallist@2.1.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
13 Packages, Including:
bcrypt-pbkdf@1.0.2
boom@2.10.1
cryptiles@2.0.5
hawk@3.1.3
hoek@2.16.3
jstransform@11.0.3
lcov-parse@0.0.10
qs@6.3.3
source-map@0.4.4
source-map@0.5.7
source-map@0.6.1
sprintf-js@1.0.3
tough-cookie@2.3.4

N/A

N/A
8 Packages, Including:
commander@2.2.0
css-stringify@1.4.1
css@1.6.0
domhandler@2.3.0
domutils@1.5.1
inherits@1.0.2
log-driver@1.2.5
uglify-js@2.4.6

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
8 Packages, Including:
coveralls@2.13.3
deeper@2.1.0
domelementtype@1.3.1
domelementtype@2.3.0
entities@2.2.0
esprima@2.7.3
esprima@3.1.3
esprima@4.0.1

BSD

Invalid
Not OSI Approved
8 Packages, Including:
diff@1.4.0
duplexer2@0.0.2
esprima-fb@15001.1.0-dev-harmony-fb
glob@3.1.21
graceful-fs@1.2.3
sntp@1.0.9
source-map@0.1.43
unique-stream@1.0.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
6 Packages, Including:
aws-sign2@0.6.0
caseless@0.11.0
forever-agent@0.6.1
oauth-sign@0.8.2
request@2.79.0
tunnel-agent@0.4.3

BSD-3-Clause OR MIT

Permissive
1 Packages, Including:
amdefine@1.0.1

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
atob@2.1.2

BSD-like

Invalid
Not OSI Approved
1 Packages, Including:
entities@1.0.0

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

(WTFPL OR MIT)

Permissive
1 Packages, Including:
opener@1.5.2

MIT/X11

Invalid
Not OSI Approved
1 Packages, Including:
optimist@0.3.7

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

12
All Dependencies CSV
β“˜ This is a list of aframe 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
browserify-css0.8.4655.27 kBMIT
prod
4
5
2
5
debug2.6.916.13 kBMIT
prod
deep-assign2.0.02.04 kBMIT
prod
envify3.4.13.04 kBMIT
prod
1
1
load-bmfont1.4.14.03 kBMIT
prod
1
object-assign4.1.12.61 kBMIT
prod
present0.0.64.36 kBMIT
prod
promise-polyfill3.1.05.48 kBMIT
prod
style-attr1.3.02.45 kBMIT
prod
three-bmfont-text2.3.07.34 kBMIT
prod
three0.83.02.86 MBMIT
prod
1
tween.js15.0.05.44 MBMIT
prod
8
40
8
10

Visualizations