Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 26, 2024 via pnpm

login-mongo 0.1.6

Simple authentication/users back-end using MongoDB
Package summary
Share
35
issues
13
critical severity
vulnerability
2
license
11
12
high severity
vulnerability
5
license
3
meta
4
8
moderate severity
vulnerability
8
2
low severity
license
2
5
licenses
27
MIT
11
N/A
2
BSD
2
other licenses
BSD-3-Clause
1
(MIT OR GPL)
1
Package created
25 Oct 2013
Version published
2 Nov 2013
Maintainers
1
Total deps
42
Direct deps
8
License
MIT

Issues

35

13 critical severity issues

critical
Recommendation: Upgrade to version 6.4.16 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 4.17.12 or later
via: lodash@2.2.1
Recommendation: Check the package code and files for license information
via: mongolian@0.1.18
Recommendation: Check the package code and files for license information
via: sinon@1.7.3
Recommendation: Check the package code and files for license information
via: sinon@1.7.3
Recommendation: Check the package code and files for license information
via: nodemailer@0.5.15
Recommendation: Check the package code and files for license information
via: mongolian@0.1.18
Recommendation: Check the package code and files for license information
via: mustache@0.7.3
Recommendation: Check the package code and files for license information
via: password-hash@1.2.2
Recommendation: Check the package code and files for license information
via: randpass@0.1.0
Recommendation: Check the package code and files for license information
via: mongolian@0.1.18
Recommendation: Check the package code and files for license information
via: mongolian@0.1.18
Recommendation: Check the package code and files for license information
via: mongolian@0.1.18
Collapse
Expand

12 high severity issues

high
Recommendation: Upgrade to version 2.2.1 or later
via: mustache@0.7.3
Recommendation: Upgrade to version 1.4.1 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.2.1
Recommendation: Upgrade to version 1.14.7 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.2.1
Recommendation: Validate that the package complies with your license policy
via: nodemailer@0.5.15
Recommendation: Validate that the package complies with your license policy
via: sinon@1.7.3
Recommendation: Validate that the package complies with your license policy
via: nodemailer@0.5.15
via: sinon@1.7.3
via: nodemailer@0.5.15
via: nodemailer@0.5.15
via: nodemailer@0.5.15
Collapse
Expand

8 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: lodash@2.2.1
Recommendation: Upgrade to version 6.6.1 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 1.14.8 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 4.17.21 or later
via: lodash@2.2.1
Recommendation: Upgrade to version 1.15.4 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 6.9.9 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 1.15.6 or later
via: nodemailer@0.5.15
Recommendation: Upgrade to version 4.17.5 or later
via: lodash@2.2.1
Collapse
Expand

2 low severity issues

low
Recommendation: Read and validate the license terms
via: nodemailer@0.5.15
Recommendation: Read and validate the license terms
via: sinon@1.7.3
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
27 Packages, Including:
abort-controller@3.0.0
addressparser@0.3.2
base64-js@1.5.1
buffer@6.0.3
directmail@0.1.8
dkim-signer@0.1.2
encoding@0.1.13
event-target-shim@5.0.1
events@3.3.0
he@0.3.6
iconv-lite@0.6.3
lodash@2.2.1
login-mongo@0.1.6
mailcomposer@0.2.12
mimelib@0.2.19
nodemailer@0.5.15
process@0.11.10
public-address@0.1.2
rai@0.1.12
readable-stream@4.5.2
safe-buffer@5.2.1
safer-buffer@2.1.2
simplesmtp@0.3.35
string_decoder@1.3.0
timed@0.1.1
underscore@1.13.6
xoauth2@0.1.8

N/A

N/A
11 Packages, Including:
buffalo@0.1.3
buster-core@0.6.4
buster-format@0.5.6
mime@1.2.11
mongolian@0.1.18
mustache@0.7.3
password-hash@1.2.2
randpass@0.1.0
taxman@0.1.1
tosource@0.1.1
waiter@0.1.1

BSD

Invalid
Not OSI Approved
2 Packages, Including:
follow-redirects@0.0.3
sinon@1.7.3

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
ieee754@1.2.1

(MIT OR GPL)

Invalid
1 Packages, Including:
punycode@1.2.4
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

8
All Dependencies CSV
β“˜ This is a list of login-mongo 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
lodash2.2.1182.38 kBMIT
prod
1
2
3
mongolian0.1.1823.21 kBUNKNOWN
prod
5
mustache0.7.340.25 kBUNKNOWN
prod
1
1
nodemailer0.5.1559.3 kBMIT
prod
2
7
5
1
password-hash1.2.25.04 kBUNKNOWN
prod
1
randpass0.1.02.38 kBUNKNOWN
prod
1
sinon1.7.3298.76 kBBSD
prod
2
2
1
timed0.1.11.53 kBMIT
prod

Visualizations