{"package":"lodash","ecosystem":"npm","latest_version":"4.18.1","description":"Lodash modular utilities.","license":"MIT","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://lodash.com/","repository":"https://github.com/lodash/lodash","downloads_weekly":128527290,"health":{"score":97,"risk":"low","breakdown":{"maintenance":25,"popularity":20,"security":25,"maturity":15,"community":12,"popularity_floor":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":0,"critical":0,"high":0,"medium":0,"low":0,"details":[]},"versions":{"latest":"4.18.1","total_count":117,"recent":["4.17.2","4.17.3","4.17.4","4.17.5","4.17.9","4.17.10","4.17.11","4.17.12","4.17.13","4.17.14","4.17.15","4.17.16","4.17.17","4.17.18","4.17.19","4.17.20","4.17.21","4.17.23","4.18.0","4.18.1"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":1,"first_published":"2012-04-23T16:37:11.912Z","last_published":"2026-04-01T21:01:20.458Z","dependencies_count":0,"dependencies":[]},"github_stats":{"stars":61271,"forks":7188,"open_issues":106,"is_archived":false,"pushed_at":"2026-09-11T18:02:54Z","subscribers_count":814},"bundle":{"size_kb":68.5,"gzip_kb":24.7,"dependency_count":0,"has_js_module":false,"has_side_effects":true,"scoped":false,"source":"bundlephobia"},"typescript":{"score":7,"has_types":true,"types_source":"definitely-typed","types_package":"@types/lodash"},"known_issues":{"bugs_count":5,"bugs_severity":{"high":2,"medium":2,"critical":1},"status_breakdown":{"fixed":5},"link":"/api/bugs/npm/lodash?version=4.18.1","scope":"version","details":[{"title":"Prototype Pollution in lodash","severity":"high","status":"fixed","affected_version":null,"fixed_version":"4.17.11","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16487"},{"title":"Command Injection in lodash","severity":"high","status":"fixed","affected_version":null,"fixed_version":"4.17.21","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23337"},{"title":"Prototype Pollution in lodash","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"4.17.5","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-3721"},{"title":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`","severity":"medium","status":"fixed","affected_version":null,"fixed_version":"4.18.0","url":"https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh"},{"title":"Prototype Pollution in lodash","severity":"critical","status":"fixed","affected_version":null,"fixed_version":"4.17.12","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10744"}]},"historical_compromise":null,"recommendation":{"action":"safe_to_use","issues":[],"use_version":"4.18.1","version_hint":null,"summary":"lodash@4.18.1 is safe to use (health: 97/100)","alternatives":[{"name":"es-toolkit","reason":"Modern, tree-shakeable, 2-3x faster","builtin":false},{"name":"lodash-es","reason":"prefer lodash-es for tree-shaking","builtin":false},{"name":"radash","reason":"Modern utility library, TypeScript-first","builtin":false}]},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/npm/lodash","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/npm/lodash","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/npm/lodash","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}