PkgRadar

npm · registry.npmjs.org

xmlui

Large Javascript Payload: 2157012 bytes

Why PkgRadar flagged 0.12.27

SeveritySignalEvidence
mediumLarge Javascript Payload2157012 bytes · package/dist/metadata/TextBox-D-3iXLdI.js
mediumLarge Javascript Payload4284472 bytes · package/dist/standalone/xmlui-standalone.umd.js
mediumLarge Javascript Payload2117248 bytes · package/dist/lib/xmlui.js
mediumLarge Javascript Payload5754174 bytes · package/dist/nodejs/bin/dist-BrzOM4ND.mjs
mediumLarge Javascript Payload7843382 bytes · package/dist/nodejs/bin/typescript-DqXqqY-f.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.30Low risk02026-06-09
0.12.30-canary-20260604162232-7d6cd98b45621e13a6ca8f08ff08c3300cfd5cc9Low risk02026-06-04
0.12.29Low risk02026-05-29
0.12.27Review322026-05-26
0.12.28Review322026-05-26

Block this in CI

PkgRadar gates xmlui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]