PkgRadar

npm · registry.npmjs.org

ai12z

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 3.13.3

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/library/p-C3lNE7QP.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/components/p-J--erGbY.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/components/p-BCJzelr9.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/library/p-CnadO0kA.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/esm/parseHelper-9rP0JS7J.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/cjs/parseHelper-Cp45LpWl.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/esm/processCarouselData-Bf2pDFsV.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/cjs/processCarouselData-YEoGs649.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.14.2Low risk02026-06-01
3.13.3Review502026-05-28
3.14.1-alpha.0Review502026-05-28

Block this in CI

PkgRadar gates ai12z (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]