Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 2,594Niche · −30% score
- Versions published
- 198
- First published
- Apr 2026
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@beyondwork/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@beyondwork/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 3435552 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 18 · status changed
Evidence
Static findings
6 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/runtime/document-runtime.cjs | 3435552 bytes | 10 |
| medium | Large Javascript Payload | package/dist/index.cjs | 7648613 bytes | 10 |
| medium | Large Javascript Payload | package/dist/prerender-worker.cjs | 2247185 bytes | 10 |
| medium | Large Javascript Payload | package/dist/tailwind.cjs | 2349848 bytes | 10 |
| medium | Large Javascript Payload | package/dist/ui-tailwind.cjs | 2349851 bytes | 10 |
| medium | Large Javascript Payload | package/dist/api/v3.cjs | 3667582 bytes | 10 |
Manifest
Package metadata
Scripts111
audit:compositor-overlaysnode scripts/ci-check-compositor-overlays.mjsbenchmark:compositor-closeoutbash scripts/run-tool-workspace-command.sh node scripts/run-real-world-browser-benchmark.mjs --target-ids table-last-cell-end --target-limit 1 --max-mutations-mean 5 --max-paragraph-content-mutations 0 --max-layout-full-total 0 --max-decoration-full-rebuilds 0benchmark:compositor-typingbash scripts/run-tool-workspace-command.sh node scripts/run-compositor-typing-perf.mjsbenchmark:real-worldbash scripts/run-tool-workspace-command.sh node scripts/run-real-world-browser-benchmark.mjsbuildNODE_OPTIONS=--max-old-space-size=8192 tsup && node scripts/build-prerender-worker-inline.mjs && node scripts/build-editor-aux-worker.mjscheck:token-referencenode scripts/generate-token-reference.mjs --checkci-check:api-v3-metadatanode scripts/ci-check-api-v3-metadata.mjsci-check:api-v3-no-ref-reexportnode scripts/ci-check-api-v3-no-ref-reexport.mjsci-check:chrome-compositionnode scripts/ci-check-chrome-composition.mjsci-check:chrome-smoke-isolationnode scripts/ci-check-chrome-smoke-isolation.mjsci-check:headless-example-importsnode scripts/ci-check-headless-example-imports.mjsci-check:layer-11-boundarynode scripts/ci-check-layer-11-boundary.mjsci-check:layer-11-boundary:updatenode scripts/ci-check-layer-11-boundary.mjs --updateci-check:no-fixture-literalsnode scripts/ci-check-no-fixture-literals.mjsci-check:no-fixture-literals:strictnode scripts/ci-check-no-fixture-literals.mjs --strictci-check:no-legacy-presentationnode scripts/ci-check-no-legacy-presentation.mjsci-check:no-session-internals-leaknode scripts/ci-check-no-session-internals-leak.mjsci-check:session-layer-puritynode scripts/ci-check-session-layer-purity.mjsci-check:snapshot-direct-readsnode scripts/ci-check-snapshot-direct-reads.mjscontext7:api-checkbash scripts/context7-export-env.sh run bash scripts/context7-api-check.shcorpus-render:assetsbash scripts/run-corpus-render-assets.shcorpus-render:assets:localnode scripts/generate-corpus-render-assets.mjscorpus-render:layoutnode scripts/organize-corpus-renders.mjsdocx:prewarm-laycachenode --import tsx scripts/prewarm-docx-laycache.tsgenerate:token-referencenode scripts/generate-token-reference.mjsgraph-oraclebash scripts/run-tool-workspace-command.sh node --import tsx services/truth-baseline/backends/word-graph-pdf/graph-oracle.tsgraph-oracle:build-staticbash scripts/run-tool-workspace-command.sh node --import tsx services/truth-baseline/backends/word-graph-pdf/graph-oracle.ts build-staticgraph-oracle:build-static:localnode --import tsx services/truth-baseline/backends/word-graph-pdf/graph-oracle.ts build-staticgraph-oracle:localnode --import tsx services/truth-baseline/backends/word-graph-pdf/graph-oracle.tsharness:devpnpm --filter @docx-react-component/react-word-editor-harness dev- …and 81 more.
Dependencies11
@radix-ui/react-popover^1.1.15@radix-ui/react-scroll-area^1.2.10@radix-ui/react-select^2.2.6@radix-ui/react-tabs^1.1.13@radix-ui/react-toggle^1.1.10@radix-ui/react-toggle-group^1.1.11@radix-ui/react-tooltip^1.2.8comlink^4.4.2fast-xml-parser^5.5.8fflate^0.8.2lucide-react^1.7.0