10
Security score
8 known advisories in v2.3.0
OpenSSF Scorecard 2.0/10
Weekly downloads
—
Unpacked size
4.4 MB
Dependencies
19
Last publish
4 years ago
Security advisories
- steal vulnerable to Regular Expression Denial of Service via source and sourceWithCommentshigh
GHSA-28v4-jf82-jvj8
- steal vulnerable to Regular Expression Denial of Service via input variablehigh
GHSA-7f3x-2wcx-hww8
- steal vulnerable to Prototype Pollution via optionName variablecritical
GHSA-8f8g-9j73-7p82
- steal vulnerable to Prototype Pollution via requestedVersion variablecritical
GHSA-93q5-3xpc-8vg3
- steal vulnerable to Prototype Pollutioncritical
GHSA-gvjw-8mmr-8f6g
- steal Inefficient Regular Expression Complexity vulnerability via string variablehigh
GHSA-rgqx-226f-2xp4
- steal vulnerable to Prototype Pollution via key variable in babel.jscritical
GHSA-vwhq-pm3r-fjm9
- steal vulnerable to Prototype Pollution via alias variablecritical
GHSA-wc4x-qmr2-rj8h
OpenSSF ScorecardJul 20, 2026
- Code-Review0
- Maintained0
- CII-Best-Practices0
- Security-Policy0
- License10
- Branch-Protection0
- Binary-Artifacts10
- SAST0
- Fuzzing0