Loading npm security reports…
Mongodb-like queries over standard arrays of objects
A $where string is evaluated in a Node VM that the source acknowledges is escapable. Untrusted query input can become host-process code execution.
Package source references a known benign dynamic code generation pattern.
dist/index.global.jsView on unpkg · L1Package source executes code through a VM context API.
dist/repl.jsView on unpkg · L66Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/index.global.jsView on unpkg · L1Package source executes code through a VM context API.
dist/repl.jsView on unpkg · L66Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L62