PkgRadar

npm · registry.npmjs.org

@findsl/web

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 1.0.0

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/chunks/chunk-4VJGV6QV.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/chunks/chunk-EAIZ2RYS.js
mediumLarge Javascript Payload9939387 bytes · package/dist/chunks/strip-browser-JP3B5WUP.js
mediumLarge Javascript Payload2052345 bytes · package/dist/worker.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.0Low risk02026-06-04
1.1.0Low risk02026-05-29
1.0.0Review442026-05-27
1.0.1Review442026-05-27
1.0.0-rc.7Review442026-05-26
1.0.0-rc.6Review442026-05-25
1.0.0-rc.5Review202026-05-24
1.0.0-rc.4Review202026-05-24
1.0.0-rc.3Review202026-05-24
1.0.0-rc.2Review202026-05-24

Related campaigns

Block this in CI

PkgRadar gates @findsl/web (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @findsl/[email protected]