Would it be possible to backport #149 to v3.9.x and/or v3.10.x and release a new package to npmjs?
This is quite an important fix as it addresses a security vulnerability. Migrating to v4.0.0 is a bigger effort that we cannot really do in the short-term.
Thanks