Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
Generated on Jan 18, 2024 via pnpm

pouchdb 6.0.1

PouchDB is a pocket-sized database
Package summary
Share
55
issues
5
critical severity
vulnerability
3
license
2
32
high severity
vulnerability
9
license
8
meta
15
8
moderate severity
vulnerability
7
license
1
10
low severity
license
10
13
licenses
161
MIT
38
ISC
14
Apache-2.0
27
other licenses
BSD-3-Clause
10
BSD
4
WTFPL
3
Apache 2
3
+ 6 more
Package created
25 Oct 2012
Version published
3 Sep 2016
Maintainers
12
Total deps
240
Direct deps
23
License
Apache-2.0

Issues

55

5 critical severity issues

critical
Recommendation: Upgrade to version 6.0.5 or later
via: pouchdb@6.0.1
Recommendation: None
via: js-extend@1.0.1
Recommendation: Upgrade to version 6.0.5 or later
via: pouchdb@6.0.1
Recommendation: Check the package code and files for license information
via: debug@2.2.0 & others
Recommendation: Check the package code and files for license information
via: leveldown@1.4.6
Collapse
Expand

32 high severity issues

high
Recommendation: Upgrade to version 3.2.2 or later
via: leveldown@1.4.6
Recommendation: Upgrade to version 2.8.2 or later
via: leveldown@1.4.6
Recommendation: Upgrade to version 4.2.1 or later
via: leveldown@1.4.6 & others
Recommendation: Upgrade to version 2.6.9 or later
via: debug@2.2.0 & others
Recommendation: Upgrade to version 9.0.1 or later
via: leveldown@1.4.6 & others
Recommendation: Upgrade to version 3.2.3 or later
via: leveldown@1.4.6
Recommendation: Upgrade to version 4.4.18 or later
via: leveldown@1.4.6
Recommendation: Validate that the package complies with your license policy
via: leveldown@1.4.6
Recommendation: Validate that the package complies with your license policy
via: level-write-stream@1.0.0
Recommendation: Validate that the package complies with your license policy
via: leveldown@1.4.6 & others
Recommendation: Validate that the package complies with your license policy
via: leveldown@1.4.6
Recommendation: Validate that the package complies with your license policy
via: websql@0.4.4
Recommendation: Validate that the package complies with your license policy
via: fruitdown@1.0.2 & others
Recommendation: Validate that the package complies with your license policy
via: websql@0.4.4
Recommendation: Validate that the license expression complies with your license policy
via: leveldown@1.4.6
via: leveldown@1.4.6 & others
via: leveldown@1.4.6 & others
via: leveldown@1.4.6
via: leveldown@1.4.6 & others
via: leveldown@1.4.6
via: leveldown@1.4.6 & others
via: leveldown@1.4.6 & others
via: leveldown@1.4.6
via: leveldown@1.4.6 & others
via: leveldown@1.4.6 & others
via: leveldown@1.4.6
via: leveldown@1.4.6 & others
via: websql@0.4.4
via: leveldown@1.4.6
via: leveldown@1.4.6
Collapse
Expand

8 moderate severity issues

moderate
Recommendation: Upgrade to version 0.6.0 or later
via: leveldown@1.4.6 & others
Recommendation: Upgrade to version 1.2.3 or later
via: leveldown@1.4.6 & others
Recommendation: None
via: leveldown@1.4.6 & others
Recommendation: Upgrade to version 2.6.9 or later
via: debug@2.2.0 & others
Recommendation: Upgrade to version 2.0.0 or later
via: debug@2.2.0 & others
Recommendation: Upgrade to version 4.1.3 or later
via: leveldown@1.4.6 & others
Recommendation: Upgrade to version 5.7.2 or later
via: leveldown@1.4.6 & others
Recommendation: Validate that the package complies with your license policy
via: leveldown@1.4.6
Collapse
Expand

10 low severity issues

low
Recommendation: Read and validate the license terms
via: leveldown@1.4.6
Recommendation: Read and validate the license terms
via: level-write-stream@1.0.0
Recommendation: Read and validate the license terms
via: leveldown@1.4.6 & others
Recommendation: Read and validate the license terms
via: leveldown@1.4.6
Recommendation: Read and validate the license terms
via: argsarray@0.0.1 & others
Recommendation: Read and validate the license terms
via: leveldown@1.4.6
Recommendation: Read and validate the license terms
via: spark-md5@2.0.2
Recommendation: Read and validate the license terms
via: websql@0.4.4
Recommendation: Read and validate the license terms
via: fruitdown@1.0.2 & others
Recommendation: Read and validate the license terms
via: websql@0.4.4
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
161 Packages, Including:
abstract-leveldown@0.12.3
abstract-leveldown@2.4.1
abstract-leveldown@2.6.3
abstract-leveldown@2.7.2
after@0.8.2
ajv@6.12.6
ansi-regex@2.1.1
ansi-styles@2.2.1
ansi@0.3.1
array-index@1.0.0
asn1@0.2.6
assert-plus@0.2.0
assert-plus@1.0.0
async@1.5.2
async@2.6.4
asynckit@0.4.0
aws4@1.12.0
balanced-match@1.0.2
bindings@1.2.1
bl@1.1.2
bl@1.2.3
bl@3.0.1
brace-expansion@1.1.11
buffer-alloc-unsafe@1.1.0
buffer-alloc@1.2.0
buffer-fill@1.0.0
buffer-from@0.1.2
chalk@1.1.3
combined-stream@1.0.8
commander@2.20.3
concat-map@0.0.1
core-util-is@1.0.2
core-util-is@1.0.3
d64@1.0.0
dashdash@1.14.1
debug@2.2.0
deep-extend@0.6.0
deferred-leveldown@1.2.2
delayed-stream@1.0.0
delegates@1.0.0
double-ended-queue@2.1.0-0
ecc-jsbn@0.1.2
end-of-stream@1.4.4
end-stream@0.1.0
errno@0.1.8
es6-iterator@2.0.3
es6-promise-pool@2.4.4
escape-string-regexp@1.0.5
execspawn@1.0.1
extend@3.0.2

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
38 Packages, Including:
abbrev@1.1.1
are-we-there-yet@1.1.7
block-stream@0.0.9
chownr@1.1.4
d@1.0.1
es5-ext@0.10.62
es6-symbol@3.1.3
ext@1.7.0
fs.realpath@1.0.0
fstream@1.0.12
gauge@1.2.7
glob@7.2.3
graceful-fs@4.2.11
har-schema@2.0.0
har-validator@2.0.6
has-unicode@2.0.1
inflight@1.0.6
inherits@2.0.1
inherits@2.0.4
ini@1.3.8
isexe@2.0.0
js-extend@1.0.1
json-stringify-safe@5.0.1
minimatch@3.1.2
next-tick@1.1.0
nopt@3.0.6
npmlog@2.0.4
once@1.4.0
osenv@0.1.5
rimraf@2.7.1
semver@5.1.1
semver@5.3.0
semver@5.7.2
tar@2.2.2
type@1.2.0
type@2.7.2
which@1.3.1
wrappy@1.0.2

Apache License 2.0

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
use-patent-claims
place-warranty
Cannot
hold-liable
use-trademark
Must
include-copyright
include-license
state-changes
include-notice
14 Packages, Including:
aws-sign2@0.6.0
aws-sign2@0.7.0
caseless@0.11.0
caseless@0.12.0
forever-agent@0.6.1
oauth-sign@0.8.2
oauth-sign@0.9.0
pouchdb@6.0.1
request@2.74.0
request@2.88.2
tunnel-agent@0.4.3
tunnel-agent@0.6.0
vuvuzela@1.0.3
websql@0.4.4

BSD 3-Clause "New" or "Revised" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
10 Packages, Including:
bcrypt-pbkdf@1.0.2
boom@2.10.1
cryptiles@2.0.5
hawk@3.1.3
hoek@2.16.3
qs@6.2.4
qs@6.5.3
sqlite3@3.1.13
tough-cookie@2.3.4
tough-cookie@2.5.0

BSD

Invalid
Not OSI Approved
4 Packages, Including:
duplexer2@0.0.2
readable-stream@0.0.4
sntp@1.0.9
url-template@2.0.8

Do What The F*ck You Want To Public License

Permissive
Not OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
sublicense
distribute
modify
Cannot
Must
rename
3 Packages, Including:
argsarray@0.0.1
expand-template@1.1.1
spark-md5@2.0.2

Apache 2

Invalid
Not OSI Approved
3 Packages, Including:
pouchdb-collections@1.0.1
tiny-queue@0.2.0
tiny-queue@0.2.1

N/A

N/A
2 Packages, Including:
ms@0.7.1
simple-mime@0.1.0

(AFL-2.1 OR BSD-3-Clause)

Permissive
1 Packages, Including:
json-schema@0.4.0

Mozilla Public License 2.0

Weakly Protective
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
place-warranty
use-patent-claims
Cannot
use-trademark
hold-liable
Must
include-copyright
include-license
disclose-source
include-original
1 Packages, Including:
node-ninja@1.0.2

(BSD-2-Clause OR MIT OR Apache-2.0)

Expression
1 Packages, Including:
rc@1.2.8

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
tweetnacl@0.14.5

BSD 2-Clause "Simplified" License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
uri-js@4.4.1
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

23
All Dependencies CSV
β“˜ This is a list of pouchdb 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
argsarray0.0.12.57 kBWTFPL
prod
1
debug2.2.010.05 kBMIT
prod
1
1
2
double-ended-queue2.1.0-06.97 kBMIT
prod
es6-promise-pool2.4.45.37 kBMIT
prod
fruitdown1.0.28.02 kBMIT
prod
1
2
inherits2.0.12.07 kBISC
prod
js-extend1.0.11.52 kBISC
prod
1
level-codec6.2.04.02 kBMIT
prod
level-write-stream1.0.01.73 kBMIT
prod
1
1
leveldown1.4.6636.21 kBMIT
prod
2
27
8
4
levelup1.3.239.39 kBMIT
prod
1
lie3.1.07.19 kBMIT
prod
localstorage-down0.6.66.61 kBMIT
prod
1
2
ltgt2.1.24.56 kBMIT
prod
memdown1.2.04.79 kBMIT
prod
pull-stream3.4.420.82 kBMIT
prod
readable-stream1.0.3315.05 kBMIT
prod
request2.74.055 kBApache-2.0
prod
11
4
1
scope-eval0.0.31.46 kBMIT
prod
spark-md52.0.29.26 kBWTFPL
prod
1
through22.0.14.31 kBMIT
prod
vuvuzela1.0.38.03 kBApache-2.0
prod
websql0.4.410.01 kBApache-2.0
prod
3
3

Visualizations