Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 1, 2024 via pnpm

compound 1.2.4

CompoundJS - MVC framework for NodeJS
Package summary
Share
31
issues
10
critical severity
vulnerability
1
license
9
14
high severity
vulnerability
3
license
4
meta
7
2
moderate severity
meta
2
5
low severity
license
5
6
licenses
9
N/A
7
MIT
3
BSD
5
other licenses
ISC
3
MIT/X11
1
WTFPL
1
Package created
18 Dec 2012
Version published
6 Jul 2016
Maintainers
1
Total deps
24
Direct deps
7
License
UNKNOWN

Issues

31

10 critical severity issues

critical
Recommendation: Upgrade to version 1.10.0 or later
via: kontroller@0.0.15
Recommendation: Check the package code and files for license information
via: kontroller@0.0.15
Recommendation: Check the package code and files for license information
via: kontroller@0.0.15
Recommendation: Check the package code and files for license information
via: compound@1.2.4
Recommendation: Check the package code and files for license information
via: ejs-ext@0.1.4-5
Recommendation: Check the package code and files for license information
via: kontroller@0.0.15
Recommendation: Check the package code and files for license information
via: jade-ext@0.0.7
Recommendation: Check the package code and files for license information
via: kontroller@0.0.15
Recommendation: Check the package code and files for license information
via: kontroller@0.0.15
Recommendation: Check the package code and files for license information
via: railway-routes@0.0.12
Collapse
Expand

14 high severity issues

high
Recommendation: Upgrade to version 3.0.2 or later
via: kontroller@0.0.15
Recommendation: Upgrade to version 3.5.0 or later
via: kontroller@0.0.15
Recommendation: Upgrade to version 3.0.5 or later
via: kontroller@0.0.15
Recommendation: Validate that the package complies with your license policy
via: kontroller@0.0.15
Recommendation: Validate that the package complies with your license policy
via: kontroller@0.0.15
Recommendation: Validate that the package complies with your license policy
via: kontroller@0.0.15
Recommendation: Validate that the package complies with your license policy
via: kontroller@0.0.15
via: coffee-script@1.7.1
via: kontroller@0.0.15
via: kontroller@0.0.15
via: kontroller@0.0.15
via: kontroller@0.0.15
via: coffee-script@1.7.1 & others
via: kontroller@0.0.15
Collapse
Expand

2 moderate severity issues

moderate
via: kontroller@0.0.15
via: kontroller@0.0.15
Collapse
Expand

5 low severity issues

low
Recommendation: Read and validate the license terms
via: kontroller@0.0.15
Recommendation: Read and validate the license terms
via: kontroller@0.0.15
Recommendation: Read and validate the license terms
via: kontroller@0.0.15
Recommendation: Read and validate the license terms
via: kontroller@0.0.15
Recommendation: Read and validate the license terms
via: yaml-js@0.3.1
Collapse
Expand

Licenses

N/A

N/A
9 Packages, Including:
commander@0.6.1
commander@2.0.0
compound@1.2.4
ejs-ext@0.1.4-5
growl@1.7.0
jade-ext@0.0.7
jade@0.26.3
mocha@1.17.1
railway-routes@0.0.12

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
coffee-script@1.7.1
debug@4.3.4
inflection@1.2.7
kontroller@0.0.15
minimatch@0.2.14
mkdirp@0.3.5
ms@2.1.2

BSD

Invalid
Not OSI Approved
3 Packages, Including:
diff@1.0.7
glob@3.2.3
graceful-fs@2.0.3

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
inherits@2.0.4
lru-cache@2.7.3
sigmund@1.0.1

MIT/X11

Invalid
Not OSI Approved
1 Packages, Including:
mkdirp@0.3.0

Do What The F*ck You Want To Public License

Permissive
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
sublicense
distribute
modify
Cannot
Must
rename
1 Packages, Including:
yaml-js@0.3.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

7
All Dependencies CSV
β“˜ This is a list of compound 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
coffee-script1.7.178.87 kBMIT
prod
2
ejs-ext0.1.4-53.41 kBUNKNOWN
prod
1
inflection1.2.76.79 kBMIT
prod
jade-ext0.0.72.98 kBUNKNOWN
prod
1
kontroller0.0.1512.72 kBMIT
prod
6
13
2
4
railway-routes0.0.1211.75 kBUNKNOWN
prod
1
yaml-js0.3.1117.5 kBWTFPL
prod
1

Visualizations