Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Apr 13, 2024 via pnpm

passport-saml-logout 0.10.2

SAML 2.0 authentication strategy for Passport
Package summary
Share
37
issues
7
critical severity
vulnerability
4
license
3
13
high severity
vulnerability
7
license
3
meta
3
10
moderate severity
vulnerability
9
meta
1
7
low severity
vulnerability
4
license
3
6
licenses
11
MIT
3
N/A
2
MIT License
3
other licenses
ISC
1
LGPL
1
(LGPL-2.0 or MIT)
1
Package created
2 Jul 2015
Version published
3 Jul 2015
Maintainers
1
Total deps
19
Direct deps
7
License
UNKNOWN

Issues

37

7 critical severity issues

critical
Recommendation: Upgrade to version 3.1.7 or later
via: xml-encryption@0.7.4
Recommendation: None
via: xml-crypto@0.3.26 & others
Recommendation: Upgrade to version 2.5.5 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 4.17.12 or later
via: xmlbuilder@2.5.2
Recommendation: Check the package code and files for license information
via: xml-encryption@0.7.4
Recommendation: Check the package code and files for license information
via: xml-encryption@0.7.4
Recommendation: Check the package code and files for license information
via: passport@0.2.2
Collapse
Expand

13 high severity issues

high
Recommendation: Upgrade to version 2.0.0 or later
via: xml-crypto@0.3.26
Recommendation: Upgrade to version 2.5.5 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 4.17.11 or later
via: xmlbuilder@2.5.2
Recommendation: Upgrade to version 0.10.0 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 1.3.0 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 1.3.0 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 4.17.21 or later
via: xmlbuilder@2.5.2
Recommendation: Validate that the package complies with your license policy
via: xml-crypto@0.3.26
Recommendation: Validate that the package complies with your license policy
via: xml-encryption@0.7.4
Recommendation: Validate that the package complies with your license policy
via: xml-crypto@0.3.26
via: xml-encryption@0.7.4
via: xml-crypto@0.3.26
via: xml-encryption@0.7.4 & others
Collapse
Expand

10 moderate severity issues

moderate
Recommendation: Upgrade to version 4.17.11 or later
via: xmlbuilder@2.5.2
Recommendation: Upgrade to version 1.3.0 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 0.5.0 or later
via: xml-crypto@0.3.26 & others
Recommendation: Upgrade to version 2.5.5 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 0.6.0 or later
via: passport@0.2.2
Recommendation: Upgrade to version 1.0.0 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 4.17.21 or later
via: xmlbuilder@2.5.2
Recommendation: None
via: xml-crypto@0.3.26 & others
Recommendation: Upgrade to version 0.5.0 or later
via: xml2js@0.4.23
via: passport@0.2.2
Collapse
Expand

7 low severity issues

low
Recommendation: Upgrade to version 4.17.5 or later
via: xmlbuilder@2.5.2
Recommendation: Upgrade to version 1.0.0 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 0.10.0 or later
via: xml-encryption@0.7.4
Recommendation: Upgrade to version 1.0.0 or later
via: xml-encryption@0.7.4
Recommendation: Read and validate the license terms
via: xml-crypto@0.3.26
Recommendation: Read and validate the license terms
via: xml-encryption@0.7.4
Recommendation: Read and validate the license terms
via: xml-crypto@0.3.26
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
11 Packages, Including:
async@0.2.10
lodash@3.2.0
passport-saml-logout@0.10.2
passport-strategy@1.0.0
passport@0.2.2
q@1.1.2
xml-encryption@0.7.4
xml2js@0.4.23
xmlbuilder@11.0.1
xmlbuilder@2.5.2
xpath.js@1.1.0

N/A

N/A
3 Packages, Including:
ejs@0.8.8
node-forge@0.2.24
pause@0.0.1

MIT License

Invalid
Not OSI Approved
2 Packages, Including:
xml-crypto@0.3.26
xpath@0.0.5

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
sax@1.3.0

LGPL

Invalid
Not OSI Approved
1 Packages, Including:
xmldom@0.1.19

(LGPL-2.0 or MIT)

Permissive
1 Packages, Including:
xmldom@0.1.31
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

7
All Dependencies CSV
β“˜ This is a list of passport-saml-logout 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
passport0.2.211.94 kBMIT
prod
1
2
q1.1.224.2 kBMIT
prod
xml-crypto0.3.2662.71 kBMIT License
prod
1
4
2
2
xml-encryption0.7.425.02 kBMIT
prod
5
7
5
4
xml2js0.4.2312.64 kBMIT
prod
1
xmlbuilder2.5.28.83 kBMIT
prod
1
2
2
1
xmldom0.1.3119.5 kB(LGPL-2.0 or MIT)
prod
1
1
2

Visualizations

All Versions