PkgRadar

npm · registry.npmjs.org

@veupathdb/mbio-site

Large Javascript Payload: 3592115 bytes

Why PkgRadar flagged 1.4.0

SeveritySignalEvidence
mediumLarge Javascript Payload3592115 bytes · package/dist/bundles/legacy/555.bundle-a9d161e01c6c22e74e3c.js
mediumLarge Javascript Payload3592141 bytes · package/dist/bundles/modern/555.bundle-a9d161e01c6c22e74e3c.js
mediumLarge Javascript Payload3804554 bytes · package/dist/bundles/legacy/605.bundle-04c1262f4a181bc7d863.js
mediumLarge Javascript Payload3817291 bytes · package/dist/bundles/modern/605.bundle-04c1262f4a181bc7d863.js
mediumLarge Javascript Payload6333456 bytes · package/dist/bundles/legacy/site-client.bundle.js
mediumLarge Javascript Payload6394259 bytes · package/dist/bundles/modern/site-client.bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.9Low risk02026-06-11
1.4.8Low risk02026-06-10
1.4.7Low risk02026-06-09
1.4.6Low risk02026-06-08
1.3.6-patch-26Low risk02026-06-08
0.0.6-organise-site-depsLow risk02026-06-08
1.4.5Low risk02026-06-07
1.4.4Low risk02026-06-03
1.4.2Low risk02026-05-29
1.4.3Low risk02026-05-29
1.4.0Review182026-05-25
1.4.1Review182026-05-25

Block this in CI

PkgRadar gates @veupathdb/mbio-site (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @veupathdb/[email protected]