PkgRadar

npm · registry.npmjs.org

@cherry-markdown/cherry-markdown-dev

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 0.11.2-202605260710.83f1f32

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/addons/advance/cherry-codeblock-echarts-plugin.esm.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/addons/advance/cherry-codeblock-echarts-plugin.js
mediumLarge Javascript Payload2129786 bytes · package/dist/cherry-markdown.core.js
mediumLarge Javascript Payload5401822 bytes · package/dist/cherry-markdown.esm.js
mediumLarge Javascript Payload13757259 bytes · package/dist/cherry-markdown.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.11.2-202606110251.1fe23d4Low risk02026-06-11
0.11.2-202606040916.2a3407fLow risk02026-06-04
0.11.2-202606040352.d800673Low risk02026-06-04
0.11.2-202606020846.43495c4Low risk02026-06-02
0.11.2-202606020628.572f204Low risk02026-06-02
0.11.2-202605260710.83f1f32Review162026-05-26
0.11.1-202605211930.4f8ea67Review542026-05-25
0.11.2-202605250717.d004126Review542026-05-25

Block this in CI

PkgRadar gates @cherry-markdown/cherry-markdown-dev (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cherry-markdown/[email protected]