PkgRadar

npm · registry.npmjs.org

ravi.bot

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 3.260527.3

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/tui/index.js
mediumLarge Javascript Payload3025898 bytes · package/dist/bundle/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.260612.1Low risk02026-06-12
3.260611.1Low risk02026-06-11
3.260609.2Low risk02026-06-09
3.260609.1Low risk02026-06-09
3.260607.3Low risk02026-06-09
3.260607.2Low risk02026-06-07
3.260607.1Low risk02026-06-07
3.260606.2Low risk02026-06-06
3.260606.1Low risk02026-06-06
3.260604.2Low risk02026-06-04
3.260604.3Low risk02026-06-04
3.260601.2Low risk02026-06-01
3.260601.1Low risk02026-06-01
3.260531.6Low risk02026-05-31
3.260531.5Low risk02026-05-31
3.260527.3Review152026-05-27
3.260527.4Review152026-05-27
3.260526.1Review222026-05-27
3.260524.2Review222026-05-25
3.260524.4Review222026-05-25
3.260524.3Review222026-05-25

Block this in CI

PkgRadar gates ravi.bot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]