a package manager for JavaScript
81%
Total Score
61
100
100
95
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-0775 npm is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.0.0 - 11.8.0. | 0.0.0 - 11.8.0 | High |
CVE-2022-29244 npm is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 7.9.0 - 8.11.0. | 7.9.0 - 8.11.0 | High |
CVE-2018-7408 npm is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.0.0 - 5.7.1. | 0.0.0 - 5.7.1 | High |
CVE-2013-4116 npm is vulnerable to Improper Link Resolution Before File Access ('Link Following') in versions 0.0.0 - 1.3.3. | 0.0.0 - 1.3.3 | Low |
CVE-2020-15095 npm is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.0 - 6.14.6. | 0.0.0 - 6.14.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ms Version ^2.1.2 | — | — |
ini Version ^6.0.0 | — | — |
tar Version ^7.5.15 | — | — |
glob Version ^13.0.6 | — | — |
nopt Version ^9.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant