My project shows dozens of security warnings (npm audit). Should I worry?

Also searched as: npm audit vulnerabilities · npm audit fix high vulnerabilities · npm audit fix vulnerabilities · Outdated dependencies OWASP

Updated 3 October 2026

Short answer

Some of them. npm audit checks every package your project uses against a database of known vulnerabilities, and an old project can easily show dozens. Many are in development tools that never reach your users. The ones in code that runs on your server or in visitors' browsers matter most. Run npm audit fix for the safe updates, test, then deal with the rest one at a time. Don't run npm audit fix --force without testing: it can jump packages to new major versions that break the app.

What's the problem

You install the project and npm prints "found 47 vulnerabilities (12 moderate, 30 high, 5 critical)". It sounds alarming, and you can't tell whether it means the app is unsafe to launch or just old.

Why it happens

  • Your app is mostly other people's code. A typical JavaScript project pulls in hundreds of packages, each of which pulls in more. A vulnerability anywhere in that tree is reported.
  • Projects sit, vulnerabilities get found. Every month a project goes without updates, more of its packages get published advisories. OWASP lists software supply chain failures third in its Top 10.
  • Severity isn't the same as risk to you. A "critical" flaw in a tool that only runs on a developer's machine during the build isn't the same as one in the code that handles your users' logins.
  • Some fixes need breaking changes. When the fix requires a new major version of something your project depends on directly, npm audit fix won't apply it without --force.

How to fix it

  1. Run npm audit fix (without --force). It applies updates that stay within the version ranges your project allows.
  2. Test the app, especially logins, payments and the main flows.
  3. See what's left that actually ships: npm audit --omit=dev leaves out development-only packages.
  4. For each remaining issue, read the advisory. Does your app use the affected feature? Is there a patched version? Update those packages deliberately, one at a time, testing between each.
  5. Use --force only on a branch, with tests, and expect to fix what breaks.
  6. Keep it from piling up again: update dependencies regularly, rather than once every few years.

When to call Preventionlabs

If a few updates clear the serious ones, you're in good shape. Call us when the fixes cascade: one major upgrade forces another, the build breaks, and the project is stuck years behind. A resurrection delivers an app that builds and starts on maintained dependencies, and dependency vulnerabilities are on the MVP-level protection checklist.

Submit your project for a free assessment

Free assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.

Sources

  1. npm: npm auditofficial docsThe audit command submits a description of the dependencies configured in your project to your default registry and asks for a report of known vulnerabilities.
  2. npm: npm auditofficial docsNote that some vulnerabilities cannot be fixed automatically and will require manual intervention or review.
  3. npm: npm auditofficial docsIf the chain of metavulnerabilities extends all the way to the root project, and it cannot be updated without changing its dependency ranges, then npm audit fix will require the --force option to apply the remediation.
  4. OWASP: OWASP Top 10:2025security standards bodyA03:2025 - Software Supply Chain Failures
← All of Is it safe?