Express depends on escape-html. It hasn't been updated since 2015.

📰 Dev.to · Pico

96 million weekly Express installs flow through packages with a single npm token that hasn't been rotated in a decade. npm audit shows zero issues. Our tool scores two of them CRITICAL.

Published 29 Apr 2026
Read full article → ← Back to Reads