Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Generated on May 18, 2024 via pnpm
Package summary
Share
22
issues
9
critical severity
vulnerability
2
license
7
6
high severity
license
1
meta
5
6
moderate severity
vulnerability
4
meta
2
1
low severity
license
1
12
licenses
279
MIT
17
ISC
15
Apache-2.0
29
other licenses
BSD-3-Clause
12
N/A
7
Artistic-2.0
4
(MIT OR Apache-2.0)
1
+ 5 more
Package created
13 Sep 2013
Version published
25 Nov 2020
Maintainers
7
Total deps
340
Direct deps
24
License
MIT

Issues

22

9 critical severity issues

critical
Recommendation: Upgrade to version 3.1.7 or later
via: ejs@2.7.4
Recommendation: Upgrade to version 1.12.1 or later
via: nodemailer-direct-transport@3.3.2
Recommendation: Check the package code and files for license information
via: loopback-connector-remote@3.4.1 & others
Recommendation: Check the package code and files for license information
via: loopback-connector-remote@3.4.1 & others
Recommendation: Check the package code and files for license information
via: loopback-connector-remote@3.4.1 & others
Recommendation: Check the package code and files for license information
via: loopback-connector-remote@3.4.1 & others
Recommendation: Check the package code and files for license information
via: loopback-connector-remote@3.4.1 & others
Recommendation: Check the package code and files for license information
via: loopback-connector-remote@3.4.1 & others
Recommendation: Check the package code and files for license information
via: uid2@0.0.3
Collapse
Expand

6 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: canonical-json@0.0.4
via: ejs@2.7.4
via: loopback-connector-remote@3.4.1 & others
via: loopback-connector-remote@3.4.1 & others
via: loopback-connector-remote@3.4.1 & others
via: loopback-connector-remote@3.4.1 & others
Collapse
Expand

6 moderate severity issues

moderate
Recommendation: Upgrade to version 4.1.3 or later
via: loopback-connector-remote@3.4.1 & others
Recommendation: Upgrade to version 0.5.0 or later
via: loopback-connector-remote@3.4.1 & others
Recommendation: None
via: loopback-connector-remote@3.4.1 & others
Recommendation: Upgrade to version 3.1.10 or later
via: ejs@2.7.4
via: loopback-connector-remote@3.4.1 & others
via: uid2@0.0.3
Collapse
Expand

1 low severity issue

low
Recommendation: Read and validate the license terms
via: canonical-json@0.0.4
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
279 Packages, Including:
@types/body-parser@1.19.5
@types/connect@3.4.38
@types/express-serve-static-core@4.19.0
@types/express@4.17.21
@types/http-errors@2.0.4
@types/mime@1.3.5
@types/node@10.17.60
@types/node@20.12.12
@types/qs@6.9.15
@types/range-parser@1.2.7
@types/send@0.17.4
@types/serve-static@1.15.7
accept-language@3.0.18
accepts@1.3.8
ajv@6.12.6
ansi-styles@4.3.0
argparse@1.0.10
array-buffer-byte-length@1.0.1
array-flatten@1.1.1
arraybuffer.prototype.slice@1.0.3
asn1@0.2.6
assert-plus@1.0.0
async@2.6.4
async@3.2.5
asynckit@0.4.0
available-typed-arrays@1.0.7
aws4@1.12.0
balanced-match@1.0.2
base64-js@1.0.2
bcp47@1.1.2
bcryptjs@2.4.3
bl@2.2.1
bluebird@3.7.2
body-parser@1.20.2
bops@0.0.7
bops@1.0.0
brace-expansion@1.1.11
brace-expansion@2.0.1
bytes@3.1.2
call-bind@1.0.7
chalk@4.1.2
cldrjs@0.5.5
color-convert@2.0.1
color-name@1.1.4
combined-stream@1.0.8
commander@2.20.3
concat-map@0.0.1
content-disposition@0.5.4
content-type@1.0.5
cookie-signature@1.0.6

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
17 Packages, Including:
fs.realpath@1.0.0
glob@7.2.3
har-schema@2.0.0
inflight@1.0.6
inherits@2.0.4
isexe@2.0.0
json-stringify-safe@5.0.1
minimatch@3.1.2
minimatch@5.1.6
once@1.4.0
sax@1.3.0
semver@5.7.2
setprototypeof@1.2.0
signal-exit@3.0.7
which@1.3.1
which@2.0.2
wrappy@1.0.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
15 Packages, Including:
aws-sign2@0.7.0
caseless@0.12.0
ejs@2.7.4
ejs@3.1.10
filelist@1.0.4
forever-agent@0.6.1
human-signals@1.1.1
jake@10.9.1
js2xmlparser@3.0.0
js2xmlparser@4.0.2
oauth-sign@0.9.0
request@2.88.2
tunnel-agent@0.6.0
xmlcreate@1.0.2
xmlcreate@2.0.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
12 Packages, Including:
bcrypt-pbkdf@1.0.2
charenc@0.0.2
crypt@0.0.2
http-status@1.7.4
isemail@3.2.0
md5@2.3.0
qs@6.11.0
qs@6.12.1
qs@6.5.3
sprintf-js@1.0.3
sprintf-js@1.1.3
tough-cookie@2.5.0

N/A

N/A
7 Packages, Including:
base64-js@0.0.2
duplex@1.0.0
msgpack-js@0.3.0
mux-demux@3.7.9
options@0.0.6
sse@0.0.8
uid2@0.0.3

Artistic License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
use-trademark
hold-liable
Must
rename
state-changes
include-original
include-install-instructions
4 Packages, Including:
strong-globalize@4.1.3
strong-globalize@5.1.0
strong-globalize@6.0.6
strong-remoting@3.17.0

(MIT OR Apache-2.0)

Permissive
1 Packages, Including:
JSONStream@1.3.5

BSD

Invalid
Not OSI Approved
1 Packages, Including:
canonical-json@0.0.4

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

MIT No Attribution

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
Cannot
Must
1 Packages, Including:
nodemailer@6.9.13

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
uri-js@4.4.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

24
All Dependencies CSV
β“˜ This is a list of loopback 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
async2.6.4120.04 kBMIT
prod
bcryptjs2.4.376.21 kBMIT
prod
bluebird3.7.2136.03 kBMIT
prod
body-parser1.20.214.75 kBMIT
prod
canonical-json0.0.44.27 kBBSD
prod
1
1
debug2.6.916.13 kBMIT
prod
depd1.1.28.81 kBMIT
prod
ejs2.7.437.03 kBApache-2.0
prod
1
1
1
express4.19.2209.73 kBMIT
prod
inflection1.13.411.51 kBMIT
prod
isemail3.2.014.05 kBBSD-3-Clause
prod
loopback-connector-remote3.4.112.06 kBMIT
prod
6
4
4
loopback-datasource-juggler3.36.1684.97 kBMIT
prod
2
loopback-filters1.1.19.92 kBMIT
prod
loopback-phase3.4.016.79 kBMIT
prod
1
nodemailer-direct-transport3.3.210.29 kBMIT
prod
1
nodemailer-stub-transport1.1.03.56 kBMIT
prod
nodemailer6.9.13491.4 kBMIT-0
prod
serve-favicon2.5.06.67 kBMIT
prod
stable0.1.83.59 kBMIT
prod
1
strong-globalize4.1.3440.68 kBArtistic-2.0
prod
1
strong-remoting3.17.0121.71 kBArtistic-2.0
prod
6
4
4
uid20.0.31.41 kBUNKNOWN
prod
1
1
underscore.string3.3.637.81 kBMIT
prod

Visualizations