PkgRadar

npm · registry.npmjs.org

@cubejs-backend/server-core

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 1.6.50

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/playground/vizard/assets/index-CXd1H6uJ.js
mediumLarge Javascript Payload3457554 bytes · package/playground/assets/index-Dp9g9mH4.js
mediumLarge Javascript Payload3101115 bytes · package/playground/vizard/assets/monaco-B_IR9uhL.js
mediumLarge Javascript Payload4841300 bytes · package/playground/vizard/assets/ts.worker-VACfgpbU.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.59Low risk02026-06-17
0.6.2Low risk02026-06-17
0.6.0Low risk02026-06-17
1.6.58Low risk02026-06-17
1.6.56Low risk02026-06-09
1.6.57Low risk02026-06-09
1.4.3Low risk02026-06-08
1.6.55Low risk02026-06-05
1.6.54Low risk02026-06-04
1.6.53Low risk02026-06-02
1.6.52Low risk02026-05-29
1.6.50Review122026-05-27
1.6.51Review122026-05-27

Block this in CI

PkgRadar gates @cubejs-backend/server-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cubejs-backend/[email protected]