See how fedorindutny compares to other vendors in security performance
An issue in NPM IP Package v.1.1.8 and before allows an attacker to execute arbitrary code and obtain sensitive information via the isPublic() function.
https://cosmosofcyberspace.github.io/npmipcve/npmipcve.html https://github.com/indutny/node-ip