Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on May 4, 2024 via pnpm

merchants 0.2.2

A framework agnostic, multi-gateway payment processing library for node.js, like Omnipay for php or ActiveMerchants for ruby
Package summary
Share
7
issues
4
high severity
vulnerability
3
meta
1
3
moderate severity
vulnerability
2
meta
1
3
licenses
10
MIT
1
ISC
1
BSD-3-Clause
Package created
16 Apr 2017
Version published
12 May 2017
Maintainers
1
Total deps
12
Direct deps
5
License
MIT

Issues

7

4 high severity issues

high
Recommendation: Upgrade to version 0.18.1 or later
via: axios@0.16.2
Recommendation: Upgrade to version 0.21.2 or later
via: axios@0.16.2
Recommendation: Upgrade to version 6.2.4 or later
via: stripe@4.25.0
via: axios@0.16.2
Collapse
Expand

3 moderate severity issues

moderate
Recommendation: Upgrade to version 0.21.1 or later
via: axios@0.16.2
Recommendation: Upgrade to version 0.28.0 or later
via: axios@0.16.2
via: https@1.0.0
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
axios@0.16.2
bluebird@2.11.0
blueimp-md5@2.19.0
follow-redirects@1.15.6
is-buffer@1.1.6
lodash.isplainobject@4.0.6
lodash@4.17.21
merchants@0.2.2
object-assign@4.1.1
stripe@4.25.0

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
https@1.0.0

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
qs@6.0.4
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

5
All Dependencies CSV
β“˜ This is a list of merchants 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
axios0.16.277.34 kBMIT
prod
3
2
blueimp-md52.19.08.65 kBMIT
prod
https1.0.0317 BISC
prod
1
lodash4.17.21311.49 kBMIT
prod
stripe4.25.040.44 kBMIT
prod
1

Visualizations