PkgRadar

npm · registry.npmjs.org

shadcn

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 0.0.0-beta.d74c6d3

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/chunk-5PAIDHKR.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.0-beta.01b72a3Low risk02026-06-10
4.11.0Low risk02026-06-08
4.10.0-rc.674ae44Low risk02026-06-01
4.10.0Low risk02026-06-01
4.9.0Low risk02026-05-31
0.0.0-beta.d74c6d3Review122026-05-29
4.8.3Review122026-05-29
0.0.0-beta.9ce411322Review122026-05-29
4.8.2Low risk02026-05-27
4.8.0Low risk02026-05-26
4.8.1Low risk02026-05-26

Block this in CI

PkgRadar gates shadcn (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]