PkgRadar

npm · registry.npmjs.org

@ucap-llm/ai-ui

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 1.2.20

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/chunk-A2AXSNBT-CnIBL4XX.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/flowDiagram-4HSFHLVR-BLzM2DTb.mjs
mediumLarge Javascript Payload7938778 bytes · package/ai-ui.umd.js
mediumLarge Javascript Payload8383416 bytes · package/index-CItM3CyQ.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.23Low risk02026-05-29
1.2.22Low risk02026-05-29
1.2.20Review202026-05-25
1.2.21Review202026-05-25

Block this in CI

PkgRadar gates @ucap-llm/ai-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ucap-llm/[email protected]