PkgRadar

npm · registry.npmjs.org

@vtex/sales-app

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 3.49.9-beta.14

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/public/2c327f8c-e0c1a03e3e500e53bb44.js
mediumLarge Javascript Payload2560769 bytes · package/public/commons-e3a77a6f282c7ddd16fb.js
mediumLarge Javascript Payload4588883 bytes · package/public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-04becb274240ee91abe2.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.50.1-beta.2Low risk02026-06-12
3.50.0Low risk02026-06-01
3.49.8Low risk02026-06-01
3.49.9-beta.14Review162026-05-28
3.49.9-beta.11Review162026-05-27
3.49.9-beta.10Review162026-05-26
3.49.9-beta.6Review162026-05-26
3.49.9-beta.9Review162026-05-26
3.49.5Review162026-05-25
3.49.9-beta.5Review162026-05-25

Block this in CI

PkgRadar gates @vtex/sales-app (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vtex/[email protected]
@vtex/sales-app — npm security scan | PkgRadar