PkgRadar

npm · registry.npmjs.org

@vibes.diy/call-ai-v2

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 2.4.4

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/apply-edits.test.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.3Low risk02026-06-12
2.5.2Low risk02026-06-11
2.5.1Low risk02026-06-10
2.5.0Low risk02026-06-10
2.5.1-dev.1Low risk02026-06-10
2.4.16Low risk02026-06-08
2.4.15Low risk02026-06-07
2.4.14Low risk02026-06-04
2.4.13Low risk02026-06-03
2.4.12Low risk02026-06-03
2.4.11Low risk02026-06-02
2.4.9Low risk02026-06-01
2.4.10Low risk02026-06-01
2.4.8Low risk02026-06-01
2.4.7Low risk02026-06-01
2.4.6Low risk02026-06-01
2.4.5Low risk02026-05-31
2.4.4Review122026-05-30
2.4.3Low risk02026-05-27
2.4.2Low risk02026-05-27
2.3.4Low risk02026-05-25
2.3.5Low risk02026-05-25

Block this in CI

PkgRadar gates @vibes.diy/call-ai-v2 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vibes.diy/[email protected]