PkgRadar

npm · registry.npmjs.org

@holoviz/panel

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 1.9.1

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/bundled/aceplot/[email protected]/src-min-noconflict/worker-html.js
mediumLarge Javascript Payload4763993 bytes · package/dist/bundled/plotlyplot/plotly-3.1.0.min.js
mediumLarge Javascript Payload2563749 bytes · package/dist/bundled/abstractvtkplot/[email protected]/vtk.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.9.3Low risk02026-06-01
1.9.3-a.2Low risk02026-05-31
1.9.3-a.0Low risk02026-05-29
1.9.3-a.1Low risk02026-05-29
1.9.1Review92026-05-27
1.9.2Review92026-05-27

Block this in CI

PkgRadar gates @holoviz/panel (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @holoviz/[email protected]