PkgRadar

PyPI · pypi.org

reviewboard

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 8.0

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · reviewboard-8.0/reviewboard/htdocs/static/lib/js/3rdparty.min.8712715b7d25.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · reviewboard-8.0/reviewboard/htdocs/static/lib/js/3rdparty.min.js
mediumPy Custom Build BackendNon-standard PEP 517 build-backend `buildthings.backend` — runs custom code at install time. · pyproject.toml
mediumObfuscation Densityhigh encoded/escaped-token density · reviewboard-8.0/package-lock.json
mediumObfuscation Densityhigh encoded/escaped-token density · reviewboard-8.0/reviewboard/htdocs/static/lib/js/3rdparty-jsonlint.min.80ae6e818326.js
mediumObfuscation Densityhigh encoded/escaped-token density · reviewboard-8.0/reviewboard/htdocs/static/lib/js/3rdparty-jsonlint.min.js
mediumObfuscation Densityhigh encoded/escaped-token density · reviewboard-8.0/reviewboard/htdocs/static/lib/js/jsonlint/index.js
mediumRemote Payloadmatched "curl " · reviewboard-8.0/reviewboard/manage.py

Scanned versions

VersionVerdictScoreScanned (UTC)
8.0Review432026-05-28

Block this in CI

PkgRadar gates reviewboard (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi reviewboard==8.0