'Insecure' tags are being applied to some packages which do not have any apparent vulnerabilities. For example [lostofs](https://github.com/mwri/lostofs/) currently has a red 'insecure' tag, see first result from the [npms.io search](https://npms.io/search?q=lostofs). Hovering over the tag it says: > Package lostofs@1.0.6 has 3 vulnerabilities. For more details, check against nodesecurity.io. However, following the [link to nodesecurity.io](https://nodesecurity.io/check/lostofs) it says there are none: > There are no known vulnerabilities for lostofs@latest or any of its dependencies.