PkgRadar

npm · registry.npmjs.org

ox

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 0.14.23

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/trusted-setups/internal/setups/mainnet.json
mediumRemote Payloadmatched "cUrl " · package/tempo/ZoneRpcAuthentication.test.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-beta.0Low risk02026-06-05
0.14.29Low risk02026-06-03
0.0.0-canary-20260603074023Low risk02026-06-03
0.14.28Low risk02026-06-02
0.0.0-canary-20260602164856Low risk02026-06-02
0.0.0-canary-20260602173636Low risk02026-06-02
0.14.27Low risk02026-05-30
0.0.0-canary-20260530125330Low risk02026-05-30
0.0.0-canary-20260529213830Low risk02026-05-29
0.14.26Low risk02026-05-29
0.14.25Low risk02026-05-27
0.14.23Review122026-05-25
0.14.24Review122026-05-25
0.14.22Review122026-05-24
0.14.21Review122026-05-24

Block this in CI

PkgRadar gates ox (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]