Skip to content
Tools / PrestaShop / Dependencies

Dependency Analysis

PrestaShop

Direct and transitive dependency freshness, license, and CVE exposure from the latest SBOM.

52% Freshness
3413 Dependencies
1310 Outdated
0 Stale
15.4 Avg Behind

Dependency List

Latest release 8.2.6

Dependency Type Current Latest Behind CVE License
form-data
npm
Transitive 4.0.0 4.0.5 12 behind 1 critical MIT
form-data
npm
Transitive 4.0.0 4.0.5 12 behind 1 critical MIT
form-data
npm
Transitive 4.0.0 4.0.5 12 behind 1 critical MIT
@babel/traverse
npm
Transitive 7.16.3 1 critical MIT
dompurify
npm
Transitive 2.4.0 10 critical Apache-2.0 OR MPL-2.0 OR (Apache-2.0 AND MPL-2.0)
fast-xml-parser
npm
Transitive 5.0.9 7 critical MIT
maildev
npm
Transitive 2.1.0 1 critical MIT
phpoffice/phpspreadsheet
composer
Direct 1.17.1 24 critical MIT
playwright
npm
Transitive 1.48.2 1.60.0 889 behind 1 high Apache-2.0
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
minimatch
npm
Transitive 3.1.2 10.2.5 91 behind 3 high ISC
path-to-regexp
npm
Transitive 0.1.7 8.4.2 50 behind 1 high MIT
semver
npm
Transitive 6.3.0 7.8.1 38 behind 1 high ISC
tar
npm
Transitive 6.2.1 7.5.16 27 behind 6 high ISC
@babel/plugin-transform-modules-systemjs
npm
Transitive 7.25.0 7.29.7 24 behind 1 high MIT
http-proxy-middleware
npm
Transitive 2.0.6 4.0.0 22 behind 3 high MIT
flatted
npm
Transitive 3.2.7 3.4.2 14 behind 2 high ISC
flatted
npm
Transitive 3.2.7 3.4.2 14 behind 2 high ISC
flatted
npm
Transitive 3.2.7 3.4.2 14 behind 2 high ISC
glob
npm
Transitive 10.4.5 13.0.6 13 behind 1 high ISC
body-parser
npm
Transitive 1.20.1 2.2.2 11 behind 1 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
picomatch
npm
Transitive 2.3.1 4.0.4 9 behind 2 high MIT
fast-uri
npm
Transitive 3.0.2 3.1.2 7 behind 2 high MIT
serialize-javascript
npm
Transitive 6.0.2 7.0.5 6 behind 2 high BSD-3-Clause
serialize-javascript
npm
Transitive 6.0.2 7.0.5 6 behind 2 high BSD-3-Clause
serialize-javascript
npm
Transitive 6.0.2 7.0.5 6 behind 2 high BSD-3-Clause
serialize-javascript
npm
Transitive 6.0.2 7.0.5 6 behind 2 high BSD-3-Clause
validator
npm
Transitive 13.15.15 13.15.35 5 behind 2 high MIT
cross-spawn
npm
Transitive 7.0.3 7.0.6 3 behind 1 high MIT
cross-spawn
npm
Transitive 7.0.3 7.0.6 3 behind 1 high MIT
cross-spawn
npm
Transitive 7.0.3 7.0.6 3 behind 1 high MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
lodash
npm
Direct 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
lodash
npm
Transitive 4.17.21 4.18.1 3 behind 3 high CC0-1.0 AND MIT
node-forge
npm
Transitive 1.3.1 1.4.0 3 behind 7 high BSD-3-Clause OR GPL-2.0 OR (BSD-3-Clause AND GPL-2.0)
socket.io-parser
npm
Transitive 4.2.4 4.2.6 3 behind 1 high MIT
braces
npm
Transitive 3.0.2 3.0.3 1 behind 1 high MIT
@xmldom/xmldom
npm
Transitive 0.9.5 5 high MIT
guzzlehttp/guzzle
composer
Direct 7.3.0 4 high MIT
immutable
npm
Transitive 4.1.0 1 high MIT
immutable
npm
Transitive 4.1.0 1 high MIT
lodash.template
npm
Transitive 4.5.0 2 high MIT
nodemailer
npm
Transitive 6.7.3 5 high MIT
path-to-regexp
npm
Transitive 0.1.10 2 high MIT
pdfjs-dist
npm
Transitive 3.6.172 1 high Apache-2.0
pear/archive_tar
composer
Direct 1.4.13 1 high BSD-3-Clause
phpunit/phpunit
composer
Direct 8.5.16 1 high BSD-3-Clause
prestashop/blockwishlist
composer
Direct 2.0.1 1 high Unknown
smarty/smarty
composer
Direct 3.1.43 4 high Unknown
symfony/symfony
composer
Direct 4.4.32 9 high MIT
tecnickcom/tcpdf
composer
Direct 6.4.1 7 high LGPL-3.0-only
twig/twig
composer
Direct 3.3.8 4 high BSD-3-Clause
vue-i18n
npm
Direct 10.0.3 4 high MIT
ws
npm
Transitive 8.11.0 1 high MIT
xlsx
npm
Transitive 0.18.5 0.18.5 Current 2 high Apache-2.0
postcss
npm
Transitive 6.0.23 8.5.15 159 behind 3 medium MIT
yaml
npm
Transitive 1.10.2 2.9.0 49 behind 1 medium ISC
yaml
npm
Transitive 1.10.2 2.9.0 49 behind 1 medium ISC
bootstrap
npm
Transitive 3.4.1 5.3.8 40 behind 2 medium CC-BY-3.0 AND MIT
qs
npm
Transitive 6.13.0 6.15.2 35 behind 2 medium BSD-3-Clause
qs
npm
Transitive 6.13.0 6.15.2 35 behind 2 medium BSD-3-Clause
nanoid
npm
Transitive 3.3.7 5.1.11 24 behind 1 medium MIT
nanoid
npm
Transitive 3.3.7 5.1.11 24 behind 1 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
brace-expansion
npm
Transitive 1.1.11 5.0.6 18 behind 2 medium MIT
express
npm
Transitive 4.18.2 5.2.1 16 behind 2 medium MIT
follow-redirects
npm
Transitive 1.15.6 1.16.0 6 behind 1 medium MIT
ajv
npm
Transitive 8.17.1 8.20.0 4 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
js-yaml
npm
Transitive 4.1.0 4.2.0 3 behind 1 medium MIT
micromatch
npm
Transitive 4.0.5 4.0.8 3 behind 1 medium MIT
@babel/helpers
npm
Transitive 7.25.6 1 medium MIT
@babel/helpers
npm
Transitive 7.25.6 1 medium MIT
@babel/runtime
npm
Transitive 7.25.6 1 medium MIT
@intlify/core-base
npm
Transitive 10.0.3 2 medium MIT
@intlify/shared
npm
Transitive 10.0.3 1 medium MIT
color-string
npm
Transitive 0.3.0 1 medium MIT
esbuild
npm
Transitive 0.16.17 1 medium MIT
guzzlehttp/psr7
composer
Direct 1.8.2 2 medium Unknown
jquery
npm
Transitive 2.2.4 4 medium MIT
moment-timezone
npm
Transitive 0.4.1 2 medium MIT
prestashop/blockreassurance
composer
Direct 5.1.1 2 medium Unknown
prestashop/productcomments
composer
Direct 5.0.1 1 medium Unknown
prestashop/ps_contactinfo
composer
Direct 3.3.0 1 medium Unknown
socket.io
npm
Transitive 4.6.0 1 medium MIT
tough-cookie
npm
Transitive 4.1.2 1 medium BSD-3-Clause
webpack-dev-server
npm
Direct 5.1.0 2 medium MIT
word-wrap
npm
Transitive 1.2.3 1 medium MIT
vue
npm
Transitive 2.7.16 3.5.35 106 behind 1 low MIT
diff
npm
Transitive 4.0.2 9.0.0 18 behind 1 low BSD-3-Clause
serve-static
npm
Transitive 1.15.0 2.2.1 9 behind 1 low MIT
cookie
npm
Transitive 0.6.0 1.1.1 8 behind 1 low MIT
send
npm
Transitive 0.18.0 1.2.1 8 behind 1 low MIT
@tootallnate/once
npm
Transitive 2.0.0 3.0.1 2 behind 1 low MIT
@tootallnate/once
npm
Transitive 2.0.0 3.0.1 2 behind 1 low MIT
@tootallnate/once
npm
Transitive 2.0.0 3.0.1 2 behind 1 low MIT
on-headers
npm
Transitive 1.0.2 1.1.0 1 behind 1 low MIT
on-headers
npm
Transitive 1.0.2 1.1.0 1 behind 1 low MIT
@keycloak/keycloak-admin-client
npm
Transitive 26.0.0 1 low Apache-2.0
webpack
npm
Direct 5.95.0 2 low MIT
webpack
npm
Direct 5.95.0 2 low MIT

License Breakdown

MIT 2476
Unknown 284
ISC 190
BSD-3-Clause 105
BSD-2-Clause 86
Apache-2.0 75
MIT-0 52
AFL-3.0 37
AFL-2.1 AND AFL-3.0 11
CC0-1.0 9
Apache-2.0 AND BSD-2-Clause 8
CC0-1.0 AND MIT 7
ISC AND MIT 6
MIT OR (CC0-1.0 AND MIT) 6
CC-BY-3.0 AND MIT 5
0BSD 4
BlueOak-1.0.0 4
OSL-3.0 4
Python-2.0 4
BSD-2-Clause AND BSD-2-Clause-Views 3
BSD-2-Clause AND BSD-3-Clause 3
CC-BY-4.0 3
Unlicense 3
Apache-2.0 AND BSD-3-Clause 2
Apache-2.0 AND MIT 2
CC-BY-3.0 2
CC-BY-SA-4.0 AND ISC 2
MIT AND MITNFA 2
MIT AND Unlicense 2
MIT AND WTFPL 2
MIT OR WTFPL OR (MIT AND WTFPL) 2
OFL-1.1 2
Apache-2.0 AND BSD-3-Clause AND LicenseRef-scancode-warranty-disclaimer 1
Apache-2.0 OR MPL-2.0 OR (Apache-2.0 AND MPL-2.0) 1
BSD-3-Clause OR GPL-2.0 OR (BSD-3-Clause AND GPL-2.0) 1
EPL-1.0 1
GPL-3.0 OR MIT OR (GPL-3.0 AND MIT) 1
LGPL-2.1-or-later 1
LGPL-3.0 AND LGPL-3.0-or-later 1
LGPL-3.0-only 1
LicenseRef-scancode-dco-1.1 AND MIT 1

CVE Severity

critical 8
high 51
medium 37
low 13
unknown 0

Beta — feedback welcome: [email protected]