high

Scripts mismatch

  • metadata

This package has inconsistent scripts in the tarball's package.json

high

Prerelease version

  • metadata

The domain of the maintainer's email address ([email protected]) was re-registered after the latest release (5.0.1) of this package. It could be that an attacker leveraged the domain by re-registering it to compromise the maintainer's NPM account

low

Deprecated

Please use SameSite lax or strict see <https://scotthelme.co.uk/csrf-is-dead/> and example usage of in @forwardemail codebase <https://github.com/forwardemail/forwardemail.net/blob/040c07f076642ddd3a1a09c63c4252609a4bc52e/config/cookies.js\#L12-L16>