PkgRadar

npm · registry.npmjs.org

@cimplify/cli

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 0.7.12

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/domains-6GJASWJU.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.23Low risk02026-06-16
0.7.22Low risk02026-06-14
0.7.21Low risk02026-06-12
0.7.20Low risk02026-06-10
0.7.19Low risk02026-06-09
0.7.18Low risk02026-06-03
0.7.17Low risk02026-05-31
0.7.16Low risk02026-05-31
0.7.15Low risk02026-05-31
0.7.14Low risk02026-05-31
0.7.12Review282026-05-31
0.7.11Review282026-05-30
0.7.10Review282026-05-30
0.7.9Review282026-05-30
0.7.7Review282026-05-29
0.7.8Review402026-05-29
0.7.6Review282026-05-28
0.7.5Review72026-05-28
0.7.4Review102026-05-27
0.7.3Review72026-05-25
0.7.2Review342026-05-24
0.6.16Review342026-05-24
0.7.1Review342026-05-24

Block this in CI

PkgRadar gates @cimplify/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cimplify/[email protected]