Gathering detailed insights and metrics for lodash-es
Gathering detailed insights and metrics for lodash-es
Gathering detailed insights and metrics for lodash-es
Gathering detailed insights and metrics for lodash-es
A modern JavaScript utility library delivering modularity, performance, & extras.
npm install lodash-es
Typescript
Module System
Node Version
NPM Version
JavaScript (97.22%)
HTML (2.24%)
EJS (0.53%)
Total Downloads
2,098,659,729
Last Day
2,538,729
Last Week
13,274,101
Last Month
57,956,924
Last Year
561,373,786
NOASSERTION License
60,298 Stars
7,666 Commits
7,064 Forks
820 Watchers
7 Branches
301 Contributors
Updated on Apr 03, 2025
Latest Version
4.17.21
Package Id
lodash-es@4.17.21
Size
149.12 kB
NPM Version
6.14.11
Node Version
14.15.5
Published on
Feb 20, 2021
Cumulative downloads
Total Downloads
Last Day
0.9%
2,538,729
Compared to previous day
Last Week
-0.5%
13,274,101
Compared to previous week
Last Month
5.5%
57,956,924
Compared to previous month
Last Year
30.3%
561,373,786
Compared to previous year
No dependencies detected.
The Lodash library exported as ES modules.
Generated using lodash-cli:
1$ lodash modularize exports=es -o ./
See the package source for more details.
9.1/10
Summary
Prototype Pollution in lodash
Affected Versions
< 4.17.14
Patched Versions
4.17.14
7.4/10
Summary
Prototype Pollution in lodash
Affected Versions
>= 3.7.0, < 4.17.20
Patched Versions
4.17.20
7.2/10
Summary
Command Injection in lodash
Affected Versions
< 4.17.21
Patched Versions
4.17.21
5.3/10
Summary
Regular Expression Denial of Service (ReDoS) in lodash
Affected Versions
< 4.17.21
Patched Versions
4.17.21
0/10
Summary
Regular Expression Denial of Service (ReDoS) in lodash
Affected Versions
< 4.17.11
Patched Versions
4.17.11
Reason
0 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10
Reason
no binaries found in the repo
Reason
security policy file detected
Details
Reason
project is fuzzed
Details
Reason
license file detected
Details
Reason
Found 8/30 approved changesets -- score normalized to 2
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Reason
91 existing vulnerabilities detected
Details
Score
Last Scanned on 2025-03-24
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More