Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 9, 2024 via pnpm

excel 1.0.1

Simple NodeJS XLSX parser.
Package summary
Share
9
issues
2
critical severity
vulnerability
1
license
1
3
high severity
license
2
meta
1
2
moderate severity
vulnerability
2
2
low severity
license
2
7
licenses
20
MIT
11
ISC
2
MIT/X11
4
other licenses
Unlicense
1
N/A
1
BSD-3-Clause
1
(LGPL-2.0 or MIT)
1
Package created
26 Aug 2012
Version published
12 Sep 2019
Maintainers
2
Total deps
37
Direct deps
3
License
MIT

Issues

9

2 critical severity issues

critical
Recommendation: None
via: xmldom@0.1.31
Recommendation: Check the package code and files for license information
via: unzipper@0.8.14
Collapse
Expand

3 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: unzipper@0.8.14
Recommendation: Validate that the package complies with your license policy
via: unzipper@0.8.14
via: xmldom@0.1.31
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 0.5.0 or later
via: xmldom@0.1.31
Recommendation: None
via: xmldom@0.1.31
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: unzipper@0.8.14
Recommendation: Read and validate the license terms
via: unzipper@0.8.14
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
20 Packages, Including:
balanced-match@1.0.2
binary@0.3.0
bluebird@3.4.7
brace-expansion@1.1.11
buffer-indexof-polyfill@1.0.2
buffer-shims@1.0.0
concat-map@0.0.1
core-util-is@1.0.3
excel@1.0.1
isarray@1.0.0
minimist@1.2.8
mkdirp@0.5.6
path-is-absolute@1.0.1
process-nextick-args@1.0.7
readable-stream@2.1.5
setimmediate@1.0.5
string_decoder@0.10.31
unzipper@0.8.14
util-deprecate@1.0.2
xpath@0.0.27

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
11 Packages, Including:
fs.realpath@1.0.0
fstream@1.0.12
glob@7.2.3
graceful-fs@4.2.11
inflight@1.0.6
inherits@2.0.4
listenercount@1.0.1
minimatch@3.1.2
once@1.4.0
rimraf@2.7.1
wrappy@1.0.2

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
chainsaw@0.1.0
traverse@0.3.9

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
big-integer@1.6.52

N/A

N/A
1 Packages, Including:
buffers@0.1.1

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
duplexer2@0.1.4

(LGPL-2.0 or MIT)

Permissive
1 Packages, Including:
xmldom@0.1.31
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

3
All Dependencies CSV
β“˜ This is a list of excel 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
unzipper0.8.1410.02 kBMIT
prod
1
2
2
xmldom0.1.3119.5 kB(LGPL-2.0 or MIT)
prod
1
1
2
xpath0.0.2736.61 kBMIT
prod

Visualizations