The package install an old jquery vulnerable to CVE-2012-6708, and some security scanner like openvas, detect it. Reproducible: Always