Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 2, 2024 via pnpm

frontail 4.5.1

streaming logs to the browser
Package summary
Share
31
issues
13
critical severity
vulnerability
1
license
12
8
high severity
vulnerability
4
meta
4
10
moderate severity
vulnerability
6
meta
4
8
licenses
115
MIT
12
N/A
7
ISC
13
other licenses
Apache-2.0
6
BSD-3-Clause
3
BSD-2-Clause
2
(AFL-2.1 OR BSD-3-Clause)
1
+ 1 more
Package created
4 Apr 2012
Version published
28 Nov 2018
Maintainers
1
Total deps
147
Direct deps
16
License
MIT

Issues

31

13 critical severity issues

critical
Recommendation: Upgrade to version 3.3.3 or later
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: commander@1.3.2
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Recommendation: Check the package code and files for license information
via: socket.io@1.7.4
Collapse
Expand

8 high severity issues

high
Recommendation: Upgrade to version 3.6.0 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 3.3.2 or later
via: socket.io@1.7.4
Recommendation: None
via: socket.io@1.7.4
Recommendation: Upgrade to version 2.6.9 or later
via: socket.io@1.7.4
via: universal-analytics@0.4.23
via: socket.io@1.7.4
via: universal-analytics@0.4.23
via: universal-analytics@0.4.23 & others
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 3.6.1 or later
via: socket.io@1.7.4
Recommendation: None
via: universal-analytics@0.4.23
Recommendation: Upgrade to version 2.4.0 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 2.6.9 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 2.0.0 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 4.1.3 or later
via: universal-analytics@0.4.23
via: socket.io@1.7.4
via: socket.io@1.7.4
via: socket.io@1.7.4
via: socket.io@1.7.4
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
115 Packages, Including:
CBuffer@0.1.5
accepts@1.3.3
after@0.8.2
ajv@6.12.6
asn1@0.2.6
assert-plus@1.0.0
asynckit@0.4.0
aws4@1.12.0
backo2@1.0.2
base64-arraybuffer@0.1.5
base64id@1.0.0
basic-auth-connect@1.0.0
byline@5.0.0
combined-stream@1.0.8
component-emitter@1.2.1
connect@3.6.6
cookie-parser@1.4.6
cookie-signature@1.0.6
cookie@0.1.5
cookie@0.3.1
cookie@0.4.1
core-util-is@1.0.2
crc@3.4.4
crypto-random-string@1.0.0
daemon-fix41@1.1.2
dashdash@1.14.1
debug@2.2.0
debug@2.3.3
debug@2.6.9
debug@4.3.4
delayed-stream@1.0.0
depd@1.1.2
destroy@1.0.4
dot-prop@4.2.1
ecc-jsbn@0.1.2
ee-first@1.1.1
encodeurl@1.0.2
engine.io-client@1.8.6
engine.io-parser@1.3.2
engine.io@1.8.5
escape-html@1.0.3
etag@1.8.1
express-session@1.15.6
extend@3.0.2
extsprintf@1.3.0
fast-deep-equal@3.1.3
fast-json-stable-stringify@2.1.0
finalhandler@1.1.0
form-data@2.3.3
fresh@0.5.2

N/A

N/A
12 Packages, Including:
arraybuffer.slice@0.0.6
better-assert@1.0.2
blob@0.0.4
callsite@1.0.0
commander@1.3.2
component-bind@1.0.0
component-emitter@1.1.2
component-inherit@0.0.3
indexof@0.0.1
ms@0.7.1
object-component@0.0.3
options@0.0.6

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
7 Packages, Including:
graceful-fs@4.2.11
har-schema@2.0.0
inherits@2.0.3
json-stringify-safe@5.0.1
setprototypeof@1.1.0
signal-exit@3.0.7
write-file-atomic@2.4.3

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
6 Packages, Including:
aws-sign2@0.7.0
caseless@0.12.0
forever-agent@0.6.1
oauth-sign@0.9.0
request@2.88.2
tunnel-agent@0.6.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
bcrypt-pbkdf@1.0.2
qs@6.5.3
tough-cookie@2.5.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
configstore@4.0.0
uri-js@4.4.1

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

16
All Dependencies CSV
β“˜ This is a list of frontail 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
CBuffer0.1.58.21 kBMIT
prod
basic-auth-connect1.0.02.77 kBMIT
prod
byline5.0.03.6 kBMIT
prod
commander1.3.210.69 kBUNKNOWN
prod
1
configstore4.0.03.14 kBBSD-2-Clause
prod
connect3.6.626.75 kBMIT
prod
cookie-parser1.4.64.2 kBMIT
prod
cookie0.1.53.66 kBMIT
prod
daemon-fix411.1.23.65 kBMIT
prod
express-session1.15.620.99 kBMIT
prod
is-docker1.1.01.53 kBMIT
prod
serve-static1.13.28.2 kBMIT
prod
socket.io1.7.419.67 kBMIT
prod
12
5
8
universal-analytics0.4.2325.02 kBMIT
prod
3
2
untildify3.0.31.54 kBMIT
prod
uuid3.3.311.83 kBMIT
prod
1

Visualizations