Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 8, 2024 via pnpm

aframe 1.4.2

A web framework for building virtual reality experiences.
Package summary
Share
1
issue
1
moderate severity
vulnerability
1
4
licenses
31
MIT
3
Apache-2.0
2
ISC
1
BSD-3-Clause
Package created
7 Oct 2015
Version published
22 Apr 2023
Maintainers
5
Total deps
37
Direct deps
11
License
MIT

Issues

1

1 moderate severity issue

moderate
Recommendation: Upgrade to version 3.7.1 or later
via: load-bmfont@1.4.1
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
31 Packages, Including:
aframe@1.4.2
base64-js@1.5.1
buffer-equal@0.0.1
buffer@6.0.3
custom-event-polyfill@1.0.7
deep-assign@2.0.0
dom-walk@0.1.2
gl-preserve-state@1.0.0
global@4.4.0
is-function@1.0.2
is-obj@1.0.1
load-bmfont@1.4.1
mime@1.6.0
min-document@2.19.0
nosleep.js@0.7.0
object-assign@4.1.1
parse-bmfont-ascii@1.0.6
parse-bmfont-binary@1.0.6
parse-bmfont-xml@1.1.6
parse-headers@2.0.5
phin@2.9.3
present@0.0.6
process@0.11.10
promise-polyfill@3.1.0
super-animejs@3.1.0
super-three@0.147.1
xhr@2.6.0
xml-parse-from-string@1.0.1
xml2js@0.5.0
xmlbuilder@11.0.1
xtend@4.0.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
3 Packages, Including:
cardboard-vr-display@1.0.19
webvr-polyfill-dpdb@1.0.18
webvr-polyfill@0.10.12

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
@ungap/custom-elements@1.3.0
sax@1.3.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
ieee754@1.2.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

11
All Dependencies CSV
β“˜ This is a list of aframe 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
@ungap/custom-elements1.3.010.59 kBISC
prod
buffer6.0.322.57 kBMIT
prod
custom-event-polyfill1.0.72.83 kBMIT
prod
deep-assign2.0.02.04 kBMIT
prod
load-bmfont1.4.14.03 kBMIT
prod
1
object-assign4.1.12.61 kBMIT
prod
present0.0.64.36 kBMIT
prod
promise-polyfill3.1.05.48 kBMIT
prod
super-animejs3.1.031.82 kBMIT
prod
super-three0.147.18.89 MBMIT
prod
webvr-polyfill0.10.1289.69 kBApache-2.0
prod

Visualizations