PkgRadar

npm · registry.npmjs.org

graphdb-workbench

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 3.4.0-RC1

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/res/swagger5/swagger-ui-bundle.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/res/swagger5/swagger-ui-es-bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.4.0Low risk02026-06-15
3.5.0-reactodia-poc-TR3Low risk02026-06-11
3.5.0-reactodia-poc-TR2Low risk02026-06-11
3.5.0-reactodia-pocLow risk02026-06-10
3.4.0-RC3Low risk02026-06-03
3.4.0-RC2Low risk02026-06-01
3.4.0-RC1Review152026-05-29
3.4.0-TR9Review152026-05-29
3.4.0-SPARQL12-TR3Review242026-05-28
3.4.0-TR8Review162026-05-27
3.4.0-SPARQL12-TR2Review162026-05-27

Block this in CI

PkgRadar gates graphdb-workbench (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]