{"package":"morgan-json","ecosystem":"npm","latest_version":"1.1.0","description":"A variant of `morgan.compile` that provides format functions that output JSON","license":"MIT","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://github.com/indexzero/morgan-json#readme","repository":"https://github.com/indexzero/morgan-json","downloads_weekly":5200,"health":{"score":36,"risk":"critical","breakdown":{"maintenance":0,"popularity":6,"security":15,"maturity":12,"community":3},"deprecated":false,"max_score":100},"vulnerabilities":{"count":1,"critical":1,"high":0,"medium":0,"low":0,"details":[{"vuln_id":"CVE-2022-25921","severity":"critical","summary":"morgan-json vulnerable to Arbitrary Code Execution","affected_versions":"<=1.1.0","fixed_version":null,"source":"osv","published_at":"2022-08-29T20:06:55Z"}]},"versions":{"latest":"1.1.0","total_count":2,"recent":["1.0.0","1.1.0"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":2,"first_published":"2016-10-20T19:17:57.751Z","last_published":"2016-10-20T21:33:45.542Z","dependencies_count":1,"dependencies":["diagnostics"]},"github_stats":null,"bundle":null,"typescript":{"score":7,"has_types":true,"types_source":"definitely-typed","types_package":"@types/morgan-json"},"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"do_not_use","issues":["Moderate health score (36/100) — verify manually","1 critical vulnerabilities"],"use_version":"1.1.0","version_hint":null,"summary":"morgan-json has critical vulnerabilities — do not use"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/npm/morgan-json","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/npm/morgan-json","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/npm/morgan-json","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"_cache":"hit","_response_ms":0}