Sherlock Forensics maintains security audit reports for 16 popular npm packages. A total of 161 known vulnerabilities are catalogued across these packages as of 2026-09-19. Each report includes CVE details and remediation guidance.
| Package | Latest Version | Vulnerabilities | Description |
|---|---|---|---|
| Next.js | 16.3.5 | 66 | The React Framework |
| Axios | 1.20.0 | 44 | Promise based HTTP client for the browser and node.js |
| Angular | 1.8.3 | 15 | HTML enhanced for web apps |
| Lodash | 4.18.1 | 10 | Lodash modular utilities. |
| Mongoose | 9.10.1 | 9 | Mongoose MongoDB ODM |
| Express.js | 5.2.1 | 5 | Fast, unopinionated, minimalist web framework |
| Webpack | 5.111.1 | 4 | Packs ECMAScript/CommonJs/AMD modules for the browser. Allows you to split your codebase into multip |
| Moment.js | 2.31.0 | 4 | Parse, validate, manipulate, and display dates |
| Vue.js | 3.5.43 | 1 | The progressive JavaScript framework for building modern web UI. |
| bcrypt | 6.0.0 | 1 | A bcrypt library for NodeJS. |
| uuid | 14.0.2 | 1 | RFC9562 UUIDs |
| Zod | 4.6.5 | 1 | TypeScript-first schema declaration and validation library with static type inference |
| TypeScript | 7.0.2 | 0 | TypeScript is a language for application scale JavaScript development |
| Tailwind CSS | 4.3.3 | 0 | A utility-first CSS framework for rapidly building custom user interfaces. |
| Prisma | 8.0.0-rc.15 | 0 | The Prisma CLI: one binary for the ORM, Composer, and the Prisma Developer Platform. |
| Yargs | 18.1.0 | 0 | yargs the modern, pirate-themed, successor to optimist. |
Audit Your Dependencies
Our vibe coding security audit scans your entire dependency tree for vulnerable packages, misconfigurations and exposed secrets.
Get a Security Audit