PkgRadar

npm · registry.npmjs.org

mdts

Known Indicator Filename: package/dist/frontend/bundle.js

Why PkgRadar flagged 0.20.1

SeveritySignalEvidence
highKnown Indicator Filenamepackage/dist/frontend/bundle.js · package/dist/frontend/bundle.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/frontend/react-syntax-highlighter_languages_refractor_purescript.bundle.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/frontend/vendors-node_modules_mermaid_dist_chunks_mermaid_core_chunk-4TB4RGXK_mjs.bundle.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/frontend/vendors-node_modules_mermaid_dist_chunks_mermaid_core_flowDiagram-DWJPFMVM_mjs.bundle.js
mediumLarge Javascript Payload12093178 bytes · package/dist/frontend/bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.20.3Low risk02026-06-01
0.20.1Review552026-05-24
0.20.2Review552026-05-24

Related campaigns

Block this in CI

PkgRadar gates mdts (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]