PkgRadar

npm · registry.npmjs.org

bootstrap-validate

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 2.2.6

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/site/themes/hugo-theme-relearn/static/js/mathjax/input/tex/extensions/ams.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/site/themes/hugo-theme-relearn/static/js/mathjax/input/mml/entities.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/site/themes/hugo-theme-relearn/static/js/mathjax/sre/sre_browser.js
mediumLarge Javascript Payload2885650 bytes · package/docs/js/mermaid.min.js
mediumLarge Javascript Payload2885650 bytes · package/site/themes/hugo-theme-relearn/static/js/mermaid.min.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.6Review382026-05-28
2.3.0Low risk02026-05-28

Block this in CI

PkgRadar gates bootstrap-validate (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]