PkgRadar

npm · registry.npmjs.org

excalibur

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 0.33.0-alpha.122

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/playground/package-lock.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.33.0-alpha.146Low risk02026-06-05
0.33.0-alpha.148Low risk02026-06-05
0.33.0-alpha.147Low risk02026-06-05
0.33.0-alpha.150Low risk02026-06-05
0.33.0-alpha.149Low risk02026-06-05
0.33.0-alpha.152Low risk02026-06-05
0.33.0-alpha.151Low risk02026-06-05
0.33.0-alpha.143Low risk02026-06-02
0.33.0-alpha.144Low risk02026-06-02
0.33.0-alpha.141Low risk02026-06-02
0.33.0-alpha.139Low risk02026-06-02
0.33.0-alpha.140Low risk02026-06-02
0.33.0-alpha.138Low risk02026-06-02
0.33.0-alpha.137Low risk02026-06-02
0.33.0-alpha.135Low risk02026-06-01
0.33.0-alpha.136Low risk02026-06-01
0.33.0-alpha.134Low risk02026-05-30
0.33.0-alpha.125Low risk02026-05-30
0.33.0-alpha.124Low risk02026-05-29
0.33.0-alpha.122Review32026-05-28
0.33.0-alpha.123Review32026-05-28
0.33.0-alpha.120Review32026-05-28
0.33.0-alpha.121Review32026-05-28

Block this in CI

PkgRadar gates excalibur (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]