PkgRadar

npm · registry.npmjs.org

@veupathdb/ortho-site

Large Javascript Payload: 3592117 bytes

Why PkgRadar flagged 1.4.0

SeveritySignalEvidence
mediumLarge Javascript Payload3592117 bytes · package/dist/bundles/legacy/555.bundle-6e5fa9199fef48ddeb95.js
mediumLarge Javascript Payload3592143 bytes · package/dist/bundles/modern/555.bundle-6e5fa9199fef48ddeb95.js
mediumLarge Javascript Payload3788827 bytes · package/dist/bundles/legacy/605.bundle-6c18eb2cfba0eba86119.js
mediumLarge Javascript Payload3801162 bytes · package/dist/bundles/modern/605.bundle-6c18eb2cfba0eba86119.js
mediumLarge Javascript Payload6948489 bytes · package/dist/bundles/legacy/site-client.bundle.js
mediumLarge Javascript Payload7018725 bytes · package/dist/bundles/modern/site-client.bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.9Low risk02026-06-11
1.4.8Low risk02026-06-10
1.4.7Low risk02026-06-10
1.4.6Low risk02026-06-08
1.3.6-patch-26Low risk02026-06-08
0.0.6-organise-site-depsLow risk02026-06-08
1.4.5Low risk02026-06-08
1.4.4Low risk02026-06-03
1.4.2Low risk02026-05-29
1.4.3Low risk02026-05-29
1.4.0Review182026-05-25
1.4.1Review182026-05-25

Block this in CI

PkgRadar gates @veupathdb/ortho-site (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @veupathdb/[email protected]
@veupathdb/ortho-site — npm security scan | PkgRadar