PkgRadar

npm · registry.npmjs.org

@tagspaces/extensions

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 1.0.249

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/libs/marked/marked.min.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/msg-viewer/libs/msgreader.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/mhtml-viewer/libs/postal-mime/postal-mime.min.js
mediumLarge Javascript Payload3877050 bytes · package/text-editor/assets/index-Cr95Gq6Y.js
mediumLarge Javascript Payload3387972 bytes · package/md-editor/build/assets/index-Dvu2hJJf.js
mediumLarge Javascript Payload3791879 bytes · package/marp-viewer/libs/marp-core.bundle.js
mediumLarge Javascript Payload2108098 bytes · package/rtf-viewer/libs/rtf/RTFJS.bundle.min.js
mediumLarge Javascript Payload7010226 bytes · package/text-editor/assets/ts.worker-BH9nVgjN.js
mediumLarge Javascript Payload2333217 bytes · package/pdf-viewer/generic/build/pdf.worker.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.251Low risk02026-06-09
1.0.250Low risk02026-06-09
1.0.246Low risk02026-06-09
1.0.249Review482026-05-27
1.0.247Review1082026-05-24
1.0.248Review1082026-05-24

Block this in CI

PkgRadar gates @tagspaces/extensions (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tagspaces/[email protected]