Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 5, 2024 via pnpm
Package summary
Share
15
issues
2
critical severity
vulnerability
1
license
1
6
high severity
license
5
meta
1
2
moderate severity
vulnerability
2
5
low severity
license
5
7
licenses
12
MIT
4
MIT/X11
4
BSD-2-Clause
6
other licenses
BSD-3-Clause
3
BSD
1
N/A
1
(LGPL-2.0 or MIT)
1
Package created
4 Nov 2012
Version published
9 Apr 2019
Maintainers
4
Total deps
26
Direct deps
10
License
BSD-3-Clause

Issues

15

2 critical severity issues

critical
Recommendation: None
via: xmldom@0.1.31
Recommendation: Check the package code and files for license information
via: unicoderegexp@0.4.1
Collapse
Expand

6 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: seq@0.3.5
Recommendation: Validate that the package complies with your license policy
via: seq@0.3.5
Recommendation: Validate that the package complies with your license policy
via: seq@0.3.5
Recommendation: Validate that the package complies with your license policy
via: seq@0.3.5
Recommendation: Validate that the package complies with your license policy
via: memoizeasync@1.1.0
via: xmldom@0.1.31
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 0.5.0 or later
via: xmldom@0.1.31
Recommendation: None
via: xmldom@0.1.31
Collapse
Expand

5 low severity issues

low
Recommendation: Read and validate the license terms
via: seq@0.3.5
Recommendation: Read and validate the license terms
via: seq@0.3.5
Recommendation: Read and validate the license terms
via: seq@0.3.5
Recommendation: Read and validate the license terms
via: seq@0.3.5
Recommendation: Read and validate the license terms
via: memoizeasync@1.1.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
deep-is@0.1.4
fast-levenshtein@2.0.6
levn@0.3.0
lodash@4.17.21
lru-cache@2.5.0
optionator@0.8.3
pegjs@0.10.0
prelude-ls@1.1.2
traverse@0.6.8
type-check@0.3.2
word-wrap@1.2.5
xpath@0.0.27

MIT/X11

Invalid
Not OSI Approved
4 Packages, Including:
chainsaw@0.0.9
hashish@0.0.4
seq@0.3.5
traverse@0.3.9

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
4 Packages, Including:
escodegen@1.14.3
esprima@4.0.1
estraverse@4.3.0
esutils@2.0.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
cldr@5.1.0
passerror@1.1.1
source-map@0.6.1

BSD

Invalid
Not OSI Approved
1 Packages, Including:
memoizeasync@1.1.0

N/A

N/A
1 Packages, Including:
unicoderegexp@0.4.1

(LGPL-2.0 or MIT)

Permissive
1 Packages, Including:
xmldom@0.1.31
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

10
All Dependencies CSV
β“˜ This is a list of cldr 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
escodegen1.14.319.63 kBBSD-2-Clause
prod
esprima4.0.150.86 kBBSD-2-Clause
prod
lodash4.17.21311.49 kBMIT
prod
memoizeasync1.1.010.67 kBBSD
prod
1
1
passerror1.1.12.48 kBBSD-3-Clause
prod
pegjs0.10.069.61 kBMIT
prod
seq0.3.510.68 kBMIT/X11
prod
4
4
unicoderegexp0.4.110.1 kBUNKNOWN
prod
1
xmldom0.1.3119.5 kB(LGPL-2.0 or MIT)
prod
1
1
2
xpath0.0.2736.61 kBMIT
prod

Visualizations