Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Mar 31, 2024 via pnpm

joola 0.7.4

The open-source data visualization framework
Package summary
Share
180
issues
57
critical severity
vulnerability
7
license
50
67
high severity
vulnerability
24
license
15
meta
28
39
moderate severity
vulnerability
22
meta
17
17
low severity
vulnerability
3
license
14
16
licenses
285
MIT
50
N/A
16
BSD-3-Clause
42
other licenses
Apache-2.0
12
ISC
10
BSD
5
Apache License, Version 2.0
2
+ 9 more
Package created
23 Jul 2014
Version published
4 Aug 2014
Maintainers
1
Total deps
393
Direct deps
45
License
GPL-3.0

Issues

180

57 critical severity issues

critical
Recommendation: Upgrade to version 15.3.0 or later
via: localeval@13.12.11
Recommendation: Upgrade to version 3.1.1 or later
via: jade@1.11.0
Recommendation: Upgrade to version 2.4.24 or later
via: jade@1.11.0
Recommendation: Upgrade to version 1.1.4 or later
via: joola.datastore-mongodb@0.0.5
Recommendation: Upgrade to version 0.5.1 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 1.12.1 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 3.3.3 or later
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: microtime@0.5.1
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: circular-json@0.1.6
Recommendation: Check the package code and files for license information
via: cloneextend@0.0.3 & others
Recommendation: Check the package code and files for license information
via: colors@0.6.2
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: connect-redis@1.4.7
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: jade@1.11.0
Recommendation: Check the package code and files for license information
via: jade@1.11.0
Recommendation: Check the package code and files for license information
via: jade@1.11.0
Recommendation: Check the package code and files for license information
via: htpasswd@2.4.6
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: deep-diff@0.1.7
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: humanize-number@0.0.2
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: joola.datastore-influxdb@0.0.5
Recommendation: Check the package code and files for license information
via: localeval@13.12.11
Recommendation: Check the package code and files for license information
via: microtime@0.5.1
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: joola.cli@0.1.0 & others
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: connect-redis@1.4.7
Recommendation: Check the package code and files for license information
via: connect@2.12.0
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: socket.io-redis@0.1.4
Recommendation: Check the package code and files for license information
via: bunyan-loggly@0.0.5
Recommendation: Check the package code and files for license information
via: jade@1.11.0
Recommendation: Check the package code and files for license information
via: connect@2.12.0 & others
Recommendation: Check the package code and files for license information
via: circular-json@0.1.6
Collapse
Expand

67 high severity issues

high
Recommendation: Upgrade to version 3.1.13 or later
via: joola.datastore-mongodb@0.0.5
Recommendation: Upgrade to version 6.0.4 or later
via: bunyan-loggly@0.0.5 & others
Recommendation: Upgrade to version 3.6.0 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 3.3.2 or later
via: joola.cli@0.1.0 & others
Recommendation: None
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 1.0.0 or later
via: connect@2.12.0
Recommendation: Upgrade to version 0.6.1 or later
via: connect@2.12.0
Recommendation: Upgrade to version 1.0.0 or later
via: connect@2.12.0
Recommendation: Upgrade to version 4.3.2 or later
via: semver@2.2.1
Recommendation: Upgrade to version 2.6.0 or later
via: jade@1.11.0
Recommendation: Upgrade to version 2.19.3 or later
via: joola.datastore-influxdb@0.0.5 & others
Recommendation: Upgrade to version 1.0.0 or later
via: joola.datastore-mongodb@0.0.5
Recommendation: Upgrade to version 0.5.2 or later
via: connect@2.12.0
Recommendation: Upgrade to version 1.4.1 or later
via: connect@2.12.0
Recommendation: Upgrade to version 4.2.1 or later
via: bunyan-loggly@0.0.5
Recommendation: None
via: bunyan-loggly@0.0.5
Recommendation: Upgrade to version 2.6.9 or later
via: connect@2.12.0 & others
Recommendation: Upgrade to version 0.7.1 or later
via: socket.io-redis@0.1.4
Recommendation: Upgrade to version 3.13.1 or later
via: js-yaml@3.0.2
Recommendation: Upgrade to version 9.0.1 or later
via: bunyan-loggly@0.0.5
Recommendation: Upgrade to version 2.29.2 or later
via: joola.datastore-influxdb@0.0.5 & others
Recommendation: Upgrade to version 2.3.3 or later
via: bunyan-loggly@0.0.5
Recommendation: None
via: bunyan-loggly@0.0.5
Recommendation: Upgrade to version 6.2.4 or later
via: bunyan-loggly@0.0.5 & others
Recommendation: Validate that the package complies with your license policy
via: js-yaml@3.0.2
Recommendation: Validate that the package complies with your license policy
via: semver@2.2.1
Recommendation: Validate that the package complies with your license policy
via: bunyan-loggly@0.0.5
Recommendation: Validate that the package complies with your license policy
via: jade@1.11.0
Recommendation: Validate that the package complies with your license policy
via: connect@2.12.0
Recommendation: Validate that the package complies with your license policy
via: joola.datastore-mongodb@0.0.5
Recommendation: Validate that the package complies with your license policy
via: joola.datastore-mongodb@0.0.5
Recommendation: Validate that the package complies with your license policy
via: joola.cli@0.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: joola@0.7.4
Recommendation: Validate that the package complies with your license policy
via: joola.datastore-mongodb@0.0.5
Recommendation: Validate that the package complies with your license policy
via: htpasswd@2.4.6
Recommendation: Validate that the package complies with your license policy
via: jade@1.11.0
Recommendation: Validate that the package complies with your license policy
via: jade@1.11.0
Recommendation: Validate that the package complies with your license policy
via: describe-json@0.0.6 & others
Recommendation: Validate that the package complies with your license policy
via: event-stream@4.0.1
via: bunyan-loggly@0.0.5
via: joola.datastore-mongodb@0.0.5
via: joola.datastore-mongodb@0.0.5
via: circular-json@0.1.6
via: coffee-script@1.7.1
via: connect@2.12.0
via: jade@1.11.0
via: bunyan-loggly@0.0.5
via: bunyan-loggly@0.0.5
via: joola.datastore-influxdb@0.0.5
via: bunyan-loggly@0.0.5
via: bunyan-loggly@0.0.5
via: jade@1.11.0
via: socket.io-redis@0.1.4
via: joola.cli@0.1.0 & others
via: joola.datastore-mongodb@0.0.5
via: coffee-script@1.7.1
via: joola.datastore-mongodb@0.0.5
via: bunyan-loggly@0.0.5
via: querystring@0.2.1
via: bunyan-loggly@0.0.5
via: joola.datastore-influxdb@0.0.5
via: bunyan-loggly@0.0.5
via: static-favicon@1.0.2
via: bunyan-loggly@0.0.5
via: jade@1.11.0
via: joola.datastore-influxdb@0.0.5
via: circular-json@0.1.6
Collapse
Expand

39 moderate severity issues

moderate
Recommendation: Upgrade to version 3.3.5 or later
via: js-yaml@3.0.2
Recommendation: Upgrade to version 3.13.0 or later
via: js-yaml@3.0.2
Recommendation: Upgrade to version 0.6.0 or later
via: bunyan-loggly@0.0.5
Recommendation: Upgrade to version 1.0.4 or later
via: connect@2.12.0
Recommendation: Upgrade to version 3.6.1 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 1.2.3 or later
via: bunyan-loggly@0.0.5
Recommendation: Upgrade to version 2.11.2 or later
via: joola.datastore-influxdb@0.0.5 & others
Recommendation: Upgrade to version 2.3.0 or later
via: bunyan-loggly@0.0.5
Recommendation: Upgrade to version 2.14.0 or later
via: connect@2.12.0
Recommendation: Upgrade to version 1.1.4 or later
via: joola.datastore-mongodb@0.0.5
Recommendation: Upgrade to version 2.4.0 or later
via: socket.io@1.7.4
Recommendation: Upgrade to version 2.68.0 or later
via: bunyan-loggly@0.0.5
Recommendation: Upgrade to version 3.0.0 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 3.5.0 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 3.4.0 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 3.5.0 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 2.0.0 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 0.11.1 or later
via: connect@2.12.0
Recommendation: Upgrade to version 3.5.0 or later
via: joola.cli@0.1.0 & others
Recommendation: Upgrade to version 5.7.2 or later
via: semver@2.2.1
Recommendation: Upgrade to version 4.1.3 or later
via: bunyan-loggly@0.0.5 & others
Recommendation: None
via: bunyan-loggly@0.0.5 & others
via: redis@4.6.13
via: jade@1.11.0
via: connect@2.12.0
via: connect@2.12.0
via: joola.cli@0.1.0 & others
via: connect@2.12.0
via: jade@1.11.0
via: jade@1.11.0
via: jade@1.11.0
via: htpasswd@2.4.6
via: joola.cli@0.1.0 & others
via: joola.cli@0.1.0 & others
via: joola.cli@0.1.0 & others
via: connect@2.12.0
via: connect@2.12.0
via: jade@1.11.0
via: connect@2.12.0 & others
Collapse
Expand

17 low severity issues

low
Recommendation: Upgrade to version 0.8.4 or later
via: connect@2.12.0
Recommendation: Upgrade to version 4.1.11 or later
via: jade@1.11.0
Recommendation: Upgrade to version 2.6.9 or later
via: connect@2.12.0 & others
Recommendation: Read and validate the license terms
via: js-yaml@3.0.2
Recommendation: Read and validate the license terms
via: semver@2.2.1
Recommendation: Read and validate the license terms
via: bunyan-loggly@0.0.5
Recommendation: Read and validate the license terms
via: jade@1.11.0
Recommendation: Read and validate the license terms
via: connect@2.12.0
Recommendation: Read and validate the license terms
via: joola.datastore-mongodb@0.0.5
Recommendation: Read and validate the license terms
via: joola.datastore-mongodb@0.0.5
via: joola.cli@0.1.0 & others
via: joola@0.7.4
Recommendation: Read and validate the license terms
via: joola.datastore-mongodb@0.0.5
Recommendation: Read and validate the license terms
via: htpasswd@2.4.6
Recommendation: Read and validate the license terms
via: jade@1.11.0
Recommendation: Read and validate the license terms
via: jade@1.11.0
Recommendation: Read and validate the license terms
via: describe-json@0.0.6 & others
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
285 Packages, Including:
@colors/colors@1.5.0
@redis/bloom@1.2.0
@redis/client@1.5.14
@redis/graph@1.1.1
@redis/json@1.0.6
@redis/search@1.1.6
@redis/time-series@1.0.5
abort-controller@3.0.0
accepts@1.3.3
accepts@1.3.8
acorn-globals@1.0.9
acorn@1.2.2
acorn@2.7.0
after@0.8.2
ajv@6.12.6
align-text@0.1.4
ansi-regex@2.1.1
ansi-styles@2.2.1
ansicolors@0.2.1
ansistyles@0.1.3
apache-crypt@1.2.6
apache-md5@1.1.8
argparse@0.1.16
array-flatten@1.1.1
asap@1.0.0
asn1@0.2.6
assert-plus@0.2.0
assert-plus@1.0.0
async@0.2.10
async@0.9.2
async@2.6.4
async@3.2.3
async@3.2.5
asynckit@0.4.0
aws4@1.12.0
backo2@1.0.2
base64-arraybuffer@0.1.5
base64-js@1.5.1
base64id@1.0.0
bcryptjs@2.4.3
benchmark@1.0.0
bindings@1.5.0
bl@1.0.3
body-parser@1.20.2
bops@0.0.7
buffer@6.0.3
bunyan-format@0.2.1
bytes@3.0.0
bytes@3.1.2
call-bind@1.0.7

N/A

N/A
50 Packages, Including:
arraybuffer.slice@0.0.6
base64-js@0.0.2
batch@0.5.0
better-assert@1.0.2
bindings@1.1.1
blob@0.0.4
buffer-crc32@0.2.1
bytes@0.2.1
callsite@1.0.0
circular-json@0.1.6
cloneextend@0.0.3
colors@0.6.2
component-bind@1.0.0
component-emitter@1.1.2
component-inherit@0.0.3
connect-redis@1.4.7
cookie-signature@1.0.1
cookie@0.1.0
css-parse@1.0.4
css-stringify@1.0.5
css@1.0.8
cycle@1.0.3
debug@0.7.4
debug@0.8.1
debug@1.0.2
deep-diff@0.1.7
fresh@0.2.0
humanize-number@0.0.2
indexof@0.0.1
joola.datastore-influxdb@0.0.5
localeval@13.12.11
microtime@0.5.1
mime@1.2.11
ms@0.6.2
ms@0.7.1
msgpack-js@0.3.0
object-component@0.0.3
options@0.0.6
pause@0.0.1
qs@0.6.6
range-parser@0.0.4
redis@0.10.1
redis@0.10.3
send@0.1.4
socket.io-adapter@0.3.1
socket.io-redis@0.1.4
timespan@2.3.0
uglify-js@2.2.5
uid2@0.0.3
wru@0.3.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
16 Packages, Including:
bcrypt-pbkdf@1.0.2
boom@2.10.1
cryptiles@2.0.5
d3@3.5.17
hawk@3.1.3
hiredis@0.5.0
hoek@2.16.3
ieee754@1.2.1
qs@5.2.1
qs@6.11.0
qs@6.5.3
source-map@0.4.4
source-map@0.5.7
tough-cookie@2.2.2
tough-cookie@2.5.0
unix-crypt-td-js@1.1.4

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
12 Packages, Including:
aws-sign2@0.6.0
aws-sign2@0.7.0
caseless@0.11.0
caseless@0.12.0
cluster-key-slot@1.1.2
forever-agent@0.6.1
oauth-sign@0.8.2
oauth-sign@0.9.0
request@2.67.0
request@2.88.2
tunnel-agent@0.4.3
tunnel-agent@0.6.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
bunyan-loggly@0.0.5
cliui@2.1.0
har-schema@2.0.0
har-validator@2.0.6
inherits@2.0.4
json-stringify-safe@5.0.1
mute-stream@0.0.8
read@1.0.7
setprototypeof@1.2.0
yallist@4.0.0

BSD

Invalid
Not OSI Approved
5 Packages, Including:
esprima@1.0.4
semver@2.2.1
sntp@1.0.9
source-map@0.1.43
stream-counter@0.2.0

Apache License, Version 2.0

Invalid
Not OSI Approved
2 Packages, Including:
bson@0.2.22
mongodb@1.4.40

GNU General Public License v3.0 only

Strongly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
2 Packages, Including:
joola.sdk@0.7.26
joola@0.7.4

Apache 2.0

Invalid
Not OSI Approved
2 Packages, Including:
kerberos@0.0.11
revalidator@0.1.8

MIT/X11

Invalid
Not OSI Approved
2 Packages, Including:
optimist@0.3.7
wordwrap@0.0.2

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
2 Packages, Including:
uglify-js@2.8.29
uri-js@4.4.1

BSD-3-Clause OR MIT

Permissive
1 Packages, Including:
amdefine@1.0.1

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

LAGPL

Invalid
Not OSI Approved
1 Packages, Including:
kindof@1.0.0

(MIT OR Apache2)

Invalid
1 Packages, Including:
pause-stream@0.0.11

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

45
All Dependencies CSV
β“˜ This is a list of joola 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
async3.2.5146.47 kBMIT
prod
benchmark1.0.049.31 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
bunyan-format0.2.16.42 kBMIT
prod
bunyan-loggly0.0.53.18 kBISC
prod
1
17
6
1
circular-json0.1.65.39 kBUNKNOWN
prod
2
2
cloneextend0.0.33.53 kBUNKNOWN
prod
1
coffee-script1.7.178.87 kBMIT
prod
2
colors0.6.26.14 kBUNKNOWN
prod
1
commander2.20.318.26 kBMIT
prod
compression1.7.47.64 kBMIT
prod
config0.4.37137 kBMIT
prod
connect-redis1.4.75.71 kBUNKNOWN
prod
2
connect2.12.077.97 kBMIT
prod
13
10
9
3
cookie0.1.53.66 kBMIT
prod
deep-diff0.1.7104.93 kBUNKNOWN
prod
1
deep-equal0.2.23.63 kBMIT
prod
describe-json0.0.65.13 kBMIT
prod
1
1
event-stream4.0.113.89 kBMIT
prod
1
eventemitter26.4.918.67 kBMIT
prod
express4.19.2209.73 kBMIT
prod
hiredis0.5.059.85 kBBSD-3-Clause
prod
htpasswd2.4.64.37 kBMIT
prod
1
1
1
1
humanize-number0.0.21.24 kBUNKNOWN
prod
1
jade1.11.0120.09 kBMIT
prod
6
7
5
4
joola.cli0.1.05.08 kBMIT
prod
15
5
10
2
joola.datastore-influxdb0.0.57.1 kBUNKNOWN
prod
2
5
3
joola.datastore-mongodb0.0.57.72 kBMIT
prod
2
9
1
3
joola.sdk0.7.261.2 MBGPL-3.0
prod
15
5
10
2
js-yaml3.0.230 kBMIT
prod
1
2
2
1
json-stringify-safe5.0.13.92 kBISC
prod
kindof1.0.04.08 kBLAGPL
prod
1
1
localeval13.12.113.65 kBUNKNOWN
prod
2
microtime0.5.13.23 kBUNKNOWN
prod
2
moment2.5.1438.77 kBMIT
prod
2
1
querystring0.2.13.33 kBMIT
prod
1
redis4.6.139.44 kBMIT
prod
1
repl.history0.1.41.84 kBMIT
prod
semver2.2.131.31 kBBSD
prod
2
1
1
socket.io-client1.7.4213.34 kBMIT
prod
12
4
5
1
socket.io-redis0.1.43.55 kBUNKNOWN
prod
11
4
2
1
socket.io1.7.419.67 kBMIT
prod
12
5
7
1
static-favicon1.0.22.49 kBMIT
prod
1
twix0.4.0273.95 kBMIT
prod
2
1
underscore1.13.6211.5 kBMIT
prod

Visualizations