PkgRadar

npm · registry.npmjs.org

@putout/bundle

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 5.4.1

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/bundle/putout.min.js
mediumLarge Javascript Payload2097515 bytes · package/bundle/putout.js
mediumLarge Javascript Payload2086050 bytes · package/bundle/putout.slim.js

Scanned versions

VersionVerdictScoreScanned (UTC)
5.5.1Low risk02026-06-05
5.4.1Review202026-05-24
5.5.0Review202026-05-24

Block this in CI

PkgRadar gates @putout/bundle (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @putout/[email protected]