PkgRadar

npm · registry.npmjs.org

@builder.io/fusion

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 0.0.5

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/estree-P1woeAuW.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/flow-Cj8Bfqbw.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/markdown-DHYtuV_q.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/prettier-BUgWab5f.js
mediumLarge Javascript Payload11420249 bytes · package/cli.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.3Low risk02026-06-11
0.0.4Low risk02026-06-11
0.0.5Review582026-05-26
0.0.6Review582026-05-26

Block this in CI

PkgRadar gates @builder.io/fusion (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @builder.io/[email protected]