Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 24, 2024 via pnpm

lazo 1.2.1

A client-server web framework built on Node.js that allows front-end developers to easily create a 100% SEO compliant, component MVC structured web application with an optimized first page load.
Package summary
Share
188
issues
50
critical severity
vulnerability
6
license
44
89
high severity
vulnerability
25
license
32
meta
32
18
moderate severity
vulnerability
16
meta
2
31
low severity
license
31
11
licenses
104
MIT
44
N/A
25
BSD
34
other licenses
ISC
12
BSD-3-Clause
9
MIT/X11
5
BSD-2-Clause
3
+ 4 more
Package created
21 Jul 2014
Version published
9 Feb 2015
Maintainers
8
Total deps
207
Direct deps
14
License
UNKNOWN

Issues

188

50 critical severity issues

critical
Recommendation: Upgrade to version 2.4.24 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 3.0.8 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 4.7.7 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 4.7.7 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 0.2.4 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@2.4.1
Recommendation: Check the package code and files for license information
via: request@2.40.0
Recommendation: Check the package code and files for license information
via: request@2.40.0
Recommendation: Check the package code and files for license information
via: request@2.40.0
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8 & others
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: request@2.40.0
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8 & others
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: request@2.40.0
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8 & others
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: request@2.40.0
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: handlebars@1.3.0
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Recommendation: Check the package code and files for license information
via: forever@0.10.8
Collapse
Expand

89 high severity issues

high
Recommendation: None
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 3.0.8 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 3.0.8 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 6.0.4 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 0.11.4 or later
via: forever@0.10.8
Recommendation: Upgrade to version 11.1.3 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 1.0.0 or later
via: forever@0.10.8
Recommendation: Upgrade to version 0.6.1 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 3.1.3 or later
via: forever@0.10.8 & others
Recommendation: Upgrade to version 1.0.0 or later
via: forever@0.10.8
Recommendation: Upgrade to version 4.3.2 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 2.6.0 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 3.0.2 or later
via: forever@0.10.8
Recommendation: Upgrade to version 1.4.1 or later
via: forever@0.10.8 & others
Recommendation: Upgrade to version 4.2.1 or later
via: crumb@3.1.0 & others
Recommendation: None
via: forever@0.10.8
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.4.1
Recommendation: Upgrade to version 9.0.1 or later
via: forever@0.10.8 & others
Recommendation: Upgrade to version 3.0.8 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 3.0.7 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 3.0.8 or later
via: handlebars@1.3.0
Recommendation: None
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 6.2.4 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 3.0.5 or later
via: forever@0.10.8
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.4.1
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: request@2.40.0
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: continuation-local-storage@3.1.0
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: request@2.40.0
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: request@2.40.0
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: request@2.40.0
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: request@2.40.0
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: continuation-local-storage@3.1.0
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: request@2.40.0
Recommendation: Validate that the package complies with your license policy
via: handlebars@1.3.0
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8 & others
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
Recommendation: Validate that the package complies with your license policy
via: crumb@3.1.0 & others
Recommendation: Validate that the package complies with your license policy
via: requirejs@2.1.11
Recommendation: Validate that the package complies with your license policy
via: forever@0.10.8
via: forever@0.10.8
via: request@2.40.0
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: crumb@3.1.0
via: forever@0.10.8
via: request@2.40.0
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: forever@0.10.8
via: request@2.40.0
via: forever@0.10.8
via: request@2.40.0
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: lazo@1.2.1
via: forever@0.10.8
via: fs-extra@0.6.3
via: forever@0.10.8 & others
via: forever@0.10.8
via: request@2.40.0
via: forever@0.10.8
via: crumb@3.1.0 & others
via: forever@0.10.8
via: request@2.40.0
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
via: crumb@3.1.0 & others
Collapse
Expand

18 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.4.1
Recommendation: Upgrade to version 0.6.0 or later
via: forever@0.10.8 & others
Recommendation: Upgrade to version 4.0.0 or later
via: handlebars@1.3.0
Recommendation: Upgrade to version 11.1.4 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 11.0.0 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 2.68.0 or later
via: forever@0.10.8 & others
Recommendation: Upgrade to version 1.12.2 or later
via: jquery@1.11.1
Recommendation: Upgrade to version 3.5.0 or later
via: jquery@1.11.1
Recommendation: Upgrade to version 3.5.0 or later
via: jquery@1.11.1
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.4.1
Recommendation: Upgrade to version 0.2.1 or later
via: crumb@3.1.0 & others
Recommendation: Upgrade to version 5.7.2 or later
via: crumb@3.1.0 & others
Recommendation: None
via: forever@0.10.8 & others
Recommendation: Upgrade to version 3.5.0 or later
via: jquery@1.11.1
Recommendation: Upgrade to version 4.17.5 or later
via: lodash@2.4.1
Recommendation: Upgrade to version 3.4.0 or later
via: jquery@1.11.1
via: forever@0.10.8
via: forever@0.10.8
Collapse
Expand

31 low severity issues

low
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: request@2.40.0
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: continuation-local-storage@3.1.0
Recommendation: Read and validate the license terms
via: crumb@3.1.0
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: request@2.40.0
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: request@2.40.0
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: request@2.40.0
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: request@2.40.0
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: continuation-local-storage@3.1.0
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: request@2.40.0
Recommendation: Read and validate the license terms
via: handlebars@1.3.0
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: forever@0.10.8 & others
Recommendation: Read and validate the license terms
via: forever@0.10.8
Recommendation: Read and validate the license terms
via: crumb@3.1.0 & others
Recommendation: Read and validate the license terms
via: forever@0.10.8
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
104 Packages, Including:
array-buffer-byte-length@1.0.1
async@0.1.22
async@0.2.10
async@0.2.9
async@0.6.2
async@0.9.2
available-typed-arrays@1.0.7
balanced-match@1.0.2
brace-expansion@1.1.11
call-bind@1.0.7
concat-map@0.0.1
core-util-is@1.0.3
deep-equal@2.2.3
define-data-property@1.1.4
define-properties@1.2.1
es-define-property@1.0.0
es-errors@1.3.0
es-get-iterator@1.1.3
eventemitter2@0.4.11
eventemitter2@0.4.14
eyes@0.1.8
for-each@0.3.3
form-data@0.1.4
fs-extra@0.6.3
function-bind@1.1.2
functions-have-names@1.2.3
get-intrinsic@1.2.4
gopd@1.0.1
handlebars@1.3.0
has-bigints@1.0.2
has-property-descriptors@1.0.2
has-proto@1.0.3
has-symbols@1.0.3
has-tostringtag@1.0.2
hasown@2.0.2
hermes-conrad@0.2.0
http-signature@0.10.1
i@0.3.7
internal-slot@1.0.7
is-arguments@1.1.1
is-array-buffer@3.0.4
is-bigint@1.0.4
is-boolean-object@1.1.2
is-callable@1.2.7
is-date-object@1.0.5
is-map@2.0.3
is-number-object@1.0.7
is-regex@1.1.4
is-set@2.0.3
is-shared-array-buffer@1.0.3

N/A

N/A
44 Packages, Including:
asn1@0.1.11
assert-plus@0.1.5
aws-sign2@0.5.0
aws-sign@0.2.0
broadway@0.2.10
broadway@0.2.7
cliff@0.1.8
colors@0.6.0-1
colors@0.6.2
combined-stream@0.0.7
cookie-jar@0.2.0
ctype@0.5.3
cycle@1.0.3
delayed-stream@0.0.5
director@1.1.10
event-stream@0.5.3
flatiron@0.3.5
forever-agent@0.2.0
forever-agent@0.5.2
forever-monitor@1.2.2
forever@0.10.8
form-data@0.0.10
mime@1.2.11
nconf@0.6.7
nconf@0.6.9
oauth-sign@0.2.0
oauth-sign@0.3.0
pkginfo@0.2.3
pkginfo@0.3.0
prompt@0.2.9
ps-tree@0.0.3
qs@0.5.6
request@2.16.6
request@2.9.203
timespan@2.0.1
tunnel-agent@0.2.0
uglify-js@2.3.6
utile@0.1.7
utile@0.2.1
watch@0.5.1
watch@0.7.0
winston@0.6.2
winston@0.7.1
winston@0.7.2

BSD

Invalid
Not OSI Approved
25 Packages, Including:
boom@0.3.8
boom@0.4.2
catbox@3.4.3
continuation-local-storage@3.1.0
crumb@3.1.0
cryptiles@0.1.3
cryptiles@0.2.2
hapi@6.7.1
hawk@0.10.2
hawk@1.1.1
hoek@0.7.6
hoek@0.9.1
joi@4.9.0
json-stringify-safe@3.0.0
kilt@1.1.1
qs@1.0.2
qs@2.4.2
semver@2.3.2
shimmer@1.0.0
sntp@0.1.4
sntp@0.2.4
source-map@0.1.43
statehood@1.2.0
stream-counter@0.2.0
wreck@3.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
fs.realpath@1.0.0
glob@7.2.3
inflight@1.0.6
inherits@2.0.4
ini@1.3.8
json-stringify-safe@5.0.1
minimatch@3.1.2
mute-stream@0.0.8
once@1.4.0
read@1.0.7
rimraf@2.7.1
wrappy@1.0.2

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
9 Packages, Including:
boom@2.10.1
catbox-memory@1.1.2
cryptiles@2.0.5
hoek@2.16.3
iron@2.1.3
items@1.1.1
shot@1.7.0
topo@1.1.0
tough-cookie@4.1.3

MIT/X11

Invalid
Not OSI Approved
5 Packages, Including:
optimist@0.2.8
optimist@0.3.5
optimist@0.3.7
optimist@0.4.0
optimist@0.6.0

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
3 Packages, Including:
async-listener@0.4.7
emitter-listener@1.0.1
isemail@1.2.0

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
2 Packages, Including:
request@2.40.0
tunnel-agent@0.4.3

BSD-3-Clause OR MIT

Permissive
1 Packages, Including:
amdefine@1.0.1

(BSD OR MIT)

Invalid
1 Packages, Including:
requirejs@2.1.11

Apache 2.0

Invalid
Not OSI Approved
1 Packages, Including:
revalidator@0.1.8
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

14
All Dependencies CSV
β“˜ This is a list of lazo 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
async0.6.218.7 kBMIT
prod
continuation-local-storage3.1.017.63 kBBSD
prod
2
2
crumb3.1.070.26 kBBSD
prod
1
34
4
11
forever0.10.824.93 kBUNKNOWN
prod
38
34
6
12
fs-extra0.6.3-MIT
prod
1
handlebars1.3.0153.42 kBMIT
prod
5
8
1
2
hapi6.7.1431 kBBSD
prod peer
1
32
4
10
hermes-conrad0.2.011.71 kBMIT
prod
jquery1.11.1896.62 kBMIT
prod
5
lodash2.4.1191.28 kBMIT
prod
1
2
3
node-dir0.1.55.46 kBMIT
prod
optimist0.6.011.86 kBMIT/X11
prod
1
1
1
1
request2.40.062.39 kBApache-2.0
prod
9
20
3
6
requirejs2.1.11227.78 kB(BSD OR MIT)
prod
1

Visualizations