Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Jan 16, 2024 via pnpm
Package summary
Share
9
issues
2
critical severity
vulnerability
2
5
high severity
vulnerability
3
meta
2
2
moderate severity
vulnerability
2
8
licenses
171
MIT
16
ISC
6
BSD-2-Clause
14
other licenses
Apache-2.0
5
BSD-3-Clause
5
0BSD
2
Python-2.0
1
+ 1 more
Package created
16 Oct 2016
Version published
16 Dec 2020
Maintainers
1
Total deps
207
Direct deps
13
License
MIT

Issues

9

2 critical severity issues

critical
Recommendation: Upgrade to version 5.0.0 or later
via: md-to-pdf@3.2.1
Recommendation: Upgrade to version 5.0.0 or later
via: md-to-pdf@3.2.1
Collapse
Expand

5 high severity issues

high
Recommendation: Upgrade to version 3.0.5 or later
via: serve-handler@6.1.3
Recommendation: Upgrade to version 4.0.10 or later
via: marked@1.2.6
Recommendation: Upgrade to version 4.0.10 or later
via: marked@1.2.6
via: chokidar@3.4.3
via: puppeteer@21.7.0
Collapse
Expand

2 moderate severity issues

moderate
Recommendation: Upgrade to version 2.0.0 or later
via: marked@1.2.6
Recommendation: Upgrade to version 7.5.2 or later
via: semver@7.3.4
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
171 Packages, Including:
@babel/code-frame@7.23.5
@babel/helper-validator-identifier@7.22.20
@babel/highlight@7.23.4
@samverschueren/stream-to-observable@0.3.1
@tootallnate/quickjs-emscripten@0.23.0
@types/node@20.11.4
@types/yauzl@2.10.3
agent-base@7.1.0
ansi-escapes@3.2.0
ansi-regex@2.1.1
ansi-regex@3.0.1
ansi-regex@5.0.1
ansi-styles@2.2.1
ansi-styles@3.2.1
ansi-styles@4.3.0
any-observable@0.3.0
arg@5.0.0
argparse@1.0.10
ast-types@0.13.4
balanced-match@1.0.2
base64-js@1.5.1
basic-ftp@5.0.4
binary-extensions@2.2.0
brace-expansion@1.1.11
braces@3.0.2
buffer-crc32@0.2.13
buffer@5.7.1
bytes@3.0.0
callsites@3.1.0
chalk@1.1.3
chalk@2.4.2
chalk@4.1.0
chokidar@3.4.3
cli-cursor@2.1.0
cli-truncate@0.2.1
code-point-at@1.1.0
color-convert@1.9.3
color-convert@2.0.1
color-name@1.1.3
color-name@1.1.4
concat-map@0.0.1
content-disposition@0.5.2
cosmiconfig@8.3.6
cross-fetch@4.0.0
data-uri-to-buffer@6.0.1
date-fns@1.30.1
debug@4.3.4
degenerator@5.0.1
elegant-spinner@1.0.1
emoji-regex@8.0.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
16 Packages, Including:
anymatch@3.1.3
b4a@1.6.4
cliui@8.0.1
get-caller-file@2.0.5
glob-parent@5.1.2
graceful-fs@4.2.11
lru-cache@6.0.0
lru-cache@7.18.3
minimatch@3.0.4
once@1.4.0
semver@7.3.4
signal-exit@3.0.7
wrappy@1.0.2
y18n@5.0.8
yallist@4.0.0
yargs-parser@21.1.1

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
6 Packages, Including:
escodegen@2.1.0
esprima@4.0.1
estraverse@5.3.0
esutils@2.0.3
extract-zip@2.0.1
webidl-conversions@3.0.1

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
5 Packages, Including:
@puppeteer/browsers@1.9.1
chromium-bidi@0.5.2
puppeteer-core@21.7.0
puppeteer@21.7.0
rxjs@6.6.7

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
5 Packages, Including:
devtools-protocol@0.0.1203626
highlight.js@10.4.1
ieee754@1.2.1
source-map@0.6.1
sprintf-js@1.0.3

BSD Zero Clause License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
include-copyright
include-license
include-original
Cannot
hold-liable
Must
2 Packages, Including:
tslib@1.14.1
tslib@2.6.2

Python License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
state-changes
1 Packages, Including:
argparse@2.0.1

(WTFPL OR MIT)

Permissive
1 Packages, Including:
path-is-inside@1.0.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

13
All Dependencies CSV
β“˜ This is a list of md-to-pdf 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
arg5.0.05.57 kBMIT
prod
chalk4.1.010.81 kBMIT
prod
chokidar3.4.325.61 kBMIT
prod
1
get-port5.1.13.55 kBMIT
prod
get-stdin8.0.02.18 kBMIT
prod
gray-matter4.0.211.44 kBMIT
prod
highlight.js10.4.1448.77 kBBSD-3-Clause
prod
iconv-lite0.6.2184.52 kBMIT
prod
listr0.14.37.68 kBMIT
prod peer
marked1.2.662.83 kBMIT
prod
2
1
puppeteer21.7.070.14 kBApache-2.0
prod
1
semver7.3.424.72 kBISC
prod
1
serve-handler6.1.313.88 kBMIT
prod
1

Visualizations