PkgRadar

npm · registry.npmjs.org

miniflare

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 4.20260521.0

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/src/workers/core/entry.worker.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/src/workers/email/send_email.worker.js
mediumLarge Javascript Payload3872645 bytes · package/dist/src/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.20260611.0Low risk02026-06-11
4.20260609.0Low risk02026-06-09
4.20260603.0Low risk02026-06-04
4.20260601.0Low risk02026-06-02
4.20260529.0Low risk02026-06-01
4.20260521.0Review102026-05-26
4.20260526.0Review102026-05-26

Block this in CI

PkgRadar gates miniflare (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]