PkgRadar

npm · registry.npmjs.org

@scratch/scratch-vm

Large Javascript Payload: 10520427 bytes

Why PkgRadar flagged 13.8.0-test-new-release-workflow.1

SeveritySignalEvidence
mediumLarge Javascript Payload10520427 bytes · package/dist/node/scratch-vm.js
mediumLarge Javascript Payload5845462 bytes · package/dist/web/scratch-vm.js

Scanned versions

VersionVerdictScoreScanned (UTC)
14.1.0Low risk02026-06-02
14.0.0Low risk02026-06-01
13.8.0-test-new-release-workflow.1Review102026-05-26
13.8.0-UEPR-297-accessibility-improvements.1Review102026-05-26

Block this in CI

PkgRadar gates @scratch/scratch-vm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @scratch/[email protected]