Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
vocabulary-js
Advanced tools
Everybody and everything has a vocabulary. Users, actions, websites, ads, memes, etc. This tool can help you track and assess relevance between vocabularies and ensure your content will be interesting for your users.
Everybody and everything has a vocabulary. Users, actions, websites, ads, memes, etc. This tool can help you track and assess relevance between vocabularies and ensure your content will be interesting for your users.
Most humans and therefore most documents and websites have limited vocabularies, usually around 20,000 words and no more than 35,000 words and rarely more than 50,000 words. Vocabularies are typically much smaller than the documents they represent. A Vocabulary() is simply a hash table of all the words you've given it and how many times it's seen the same word. In this way, every word is ranked by the frequency and size of the word. Like any json object, you can store a vocabulary anyway you like. Given their small size, I cache them locally in window.localStorage and can store them permanently in a NoSql db if desired. You really only need to store a user's vocabulary as they click around your site, return, etc. A page's vocabulary should be created dynamically by the client and independently of the CMS, etc.
Vocabulary() can run on the server (Node) or the client (Javascript). It does not depend on jQuery or any other libraries, but is compatible of course.
It's just a tiny amount of javascript, so you can include it in the browser.
<html>
<head>...</head>
<body>
...
<script src="Vocabulary.js"></script>
</body>
</html>
or on the server
const Vocabulary = require('Vocabulary.js');
As a user, I want to be "heard" and "known" as I click around your site(s), so that when your sight suggests other products, stories or opportunities they will be relevant to me and my demonstrated interests.
let userVocabulary = new Vocabulary();
userVocabulary.add("all the words on the page");
button.click(() => userVocabulary.add("some words associated with this button"));
As a programmer, I want to maintain a user's vocabulary and then present the user with relevant options in the dynamic components on the site.
let preferences = usersVocabulary.order("shoes hats underwear");
switch(preferences[0]) {
case "shoes":
displayShoes();
break;
case "hats":
displayHats();
break;
case "underwear":
displayUnderwear();
break;
}
class Vocabulary {
constructor(text){} // add initial words to my vocabulary
add(text){} // add more words to my vocabulary, parse, etc.
addString(word, count){} // add one word or phrase without parsing
// count defaults to 1, unless you want to "seed" a word with a high count
addVocabulary(that){} // combine two vocabularies
rank(word){} // calculate the rank of a word being used in the vocabulary
order(words){} // given a list of words, sort them in order of rank
relevance(that){} // calculate how relevant "that" vocabulary is to me
}
Run node tests
You'll need to install npm, node, and mocha to run these tests in a terminal https://www.npmjs.com/package/mocha
Pull requests welcome! Please add unit tests to tests.js for any new functions.
None. Let's keep it that way please.
Copyright (c) 2019 ChadSteele.com
Permission to use, copy, modify, and/or distribute this software for any purpose with or without fee is hereby granted, provided that the above copyright notice and this permission notice appear in all copies.
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
Hire me! ChadSteele.com
FAQs
Everybody and everything has a vocabulary. Users, actions, websites, ads, memes, etc. This tool can help you track and assess relevance between vocabularies and ensure your content will be interesting for your users.
We found that vocabulary-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.