PkgRadar

npm · registry.npmjs.org

@rootauth/core

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 2.1.0

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/index.cjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/index.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.2-beta.8Low risk02026-06-08
2.1.2-beta.7Low risk02026-06-08
2.1.2-beta.6Low risk02026-06-08
2.1.2-beta.5Low risk02026-06-08
2.1.2-beta.4Low risk02026-06-05
2.1.2-beta.3Low risk02026-06-05
2.1.2-beta.1Low risk02026-06-04
2.1.2-beta.2Low risk02026-06-04
2.1.2-beta.0Low risk02026-06-03
2.1.2Low risk02026-06-02
2.1.0-beta.4Low risk02026-06-01
2.1.0-beta.3Low risk02026-06-01
2.1.0-beta.2Low risk02026-06-01
2.1.0-beta.1Low risk02026-06-01
2.1.0Review242026-05-28
2.1.0-beta.0Review242026-05-28
1.0.32-beta.19Review162026-05-27
1.0.32-beta.20Review242026-05-27
1.0.32-beta.13Review242026-05-26
1.0.33-beta.0Review162026-05-26
1.0.32-beta.11Review242026-05-25
1.0.32-beta.9Low risk02026-05-24
1.0.32-beta.10Low risk02026-05-24

Block this in CI

PkgRadar gates @rootauth/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @rootauth/[email protected]