Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Jan 26, 2024 via pnpm
Package summary
Share
8
issues
1
critical severity
license
1
6
high severity
vulnerability
1
meta
5
1
low severity
vulnerability
1
6
licenses
82
MIT
7
ISC
2
BSD-3-Clause
3
other licenses
(MPL-2.0 OR Apache-2.0)
1
N/A
1
BSD-2-Clause
1
Package created
26 Aug 2014
Version published
15 Sep 2022
Maintainers
49
Total deps
94
Direct deps
17
License
MIT

Issues

8

1 critical severity issue

critical
Recommendation: Check the package code and files for license information
via: jsonp@0.2.1
Collapse
Expand

6 high severity issues

high
Recommendation: Upgrade to version 2.6.7 or later
via: react-dom@15.7.0 & others
via: react-dom@15.7.0 & others
via: react-dom@15.7.0 & others
via: react-dom@15.7.0 & others
via: react-dom@15.7.0 & others
via: trim@1.0.1
Collapse
Expand

1 low severity issue

low
Recommendation: Upgrade to version 2.6.1 or later
via: react-dom@15.7.0 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
82 Packages, Including:
@babel/runtime@7.23.9
asap@2.0.6
asynckit@0.4.0
auth0-js@9.24.1
auth0-lock@11.34.0
auth0-password-policies@1.0.2
base64-js@1.5.1
blueimp-md5@2.19.0
call-bind@1.0.5
classnames@2.5.1
combined-stream@1.0.8
component-emitter@1.3.1
cookiejar@2.1.4
core-js@1.2.7
create-react-class@15.7.0
crypto-js@4.2.0
debug@2.6.9
debug@4.3.4
define-data-property@1.1.1
delayed-stream@1.0.0
dom-helpers@3.4.0
encoding@0.1.13
es6-promise@4.2.8
fast-safe-stringify@2.1.1
fbjs@0.8.18
form-data@4.0.0
formidable@2.1.2
function-bind@1.1.2
get-intrinsic@1.2.2
gopd@1.0.1
has-property-descriptors@1.0.1
has-proto@1.0.1
has-symbols@1.0.3
hasown@2.0.0
hexoid@1.0.0
iconv-lite@0.6.3
idtoken-verifier@2.2.4
immutable@3.8.2
is-stream@1.1.0
isomorphic-fetch@2.2.1
js-cookie@2.2.1
js-tokens@4.0.0
jsbn@1.1.0
loose-envify@1.4.0
methods@1.1.2
mime-db@1.52.0
mime-types@2.1.35
mime@2.6.0
minimist@1.2.8
ms@2.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
dezalgo@1.0.4
inherits@2.0.4
lru-cache@6.0.0
once@1.4.0
semver@7.5.4
wrappy@1.0.2
yallist@4.0.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
qs@6.11.2
react-transition-group@2.9.0

(MPL-2.0 OR Apache-2.0)

Permissive
1 Packages, Including:
dompurify@2.4.7

N/A

N/A
1 Packages, Including:
jsonp@0.2.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
webidl-conversions@3.0.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

17
All Dependencies CSV
β“˜ This is a list of auth0-lock 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
auth0-js9.24.11.31 MBMIT
prod
auth0-password-policies1.0.2966 BMIT
prod
blueimp-md52.19.08.65 kBMIT
prod
classnames2.5.18.46 kBMIT
prod
dompurify2.4.7199.36 kB(MPL-2.0 OR Apache-2.0)
prod
immutable3.8.2103.13 kBMIT
prod
jsonp0.2.13.24 kBUNKNOWN
prod
1
node-fetch2.7.043.6 kBMIT
prod
password-sheriff1.1.17.04 kBMIT
prod
prop-types15.8.122.12 kBMIT
prod
qs6.11.252 kBBSD-3-Clause
prod
react-dom15.7.0512.73 kBMIT
prod peer
5
1
react-transition-group2.9.037.92 kBBSD-3-Clause
prod
5
1
react15.7.0140.13 kBMIT
prod peer
4
1
trim1.0.11.75 kBMIT
prod
1
url-join1.1.01.75 kBMIT
prod
validator13.11.0176.41 kBMIT
prod

Visualizations