PkgRadar

Package evidence

@markw65/[email protected]

Obfuscation Density: high encoded/escaped-token density

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
240
Versions published
146Mature · −50% score
First published
Apr 2022
Publisher
markw65

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Looks clean — keep monitoring

No high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@markw65/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@markw65/[email protected]"],"fail_on":"review"}'
Publishermarkw65
Artifact bytes284,115
Previous version1.1.99
Published2026-05-31T23:49:15.112Z
SHA-2560b51918a1788883313b84d4de737f2535c5d119ef34625751aa546d3f18503d7

Why flagged

What the scanner saw

Obfuscation Density: high encoded/escaped-token density

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

low
Last checked
lowRisk
0Score
1.1.100Version
Status history (1 event)
  1. newavailable · risk low · score 0 · status changed

Evidence

Static findings

1 static · 0 from release diff · showing high-signal first.

No high-signal findings — see all findings below.

Show all 1 findings (low-signal and informational)
SeverityKindPathDetailPoints
lowObfuscation Densitypackage/build/chunk-E3RARYDH.cjshigh encoded/escaped-token density0

Manifest

Package metadata

Scripts22
  • build-debugnode esbuild.mjs
  • build-releasenode esbuild.mjs --release
  • eslintnpx eslint .
  • prepacknode esbuild.mjs --release && mkdir -p bin && cp test/cft-font-info.js bin
  • prettier-livetest -z "$(git status --untracked-files=no --porcelain || echo dirty)" && npm install ../prettier-plugin-monkeyc && git commit -am 'prettier-plugin-monkeyc-live'
  • prettier-packagenpm install; npm install @markw65/prettier-plugin-monkeyc; git commit -am "Update to $(npm list @markw65/prettier-plugin-monkeyc | sed -ne 's/^.*\(@markw65\/prettier-plugin-monkeyc\)/\1/p')"
  • testnpm run test-mocha && npm run test-analysis && npm run test-optimized && npm run test-unopt && npm run test-post-only && npm run test-tiny && npm run test-remote && npm run test-remote-tests && npm run test-personality
  • test-analysisnode test/test.js --showInfo --typeCheckLevel Strict --product=fr955 --sourceFile "test/analysis/*.mc"
  • test-garmin-optnode test/test.js --typeCheckLevel Strict --skipOptimization --garminOptLevel=2 --run-tests --product=fenix5 --product=fr235 --jungle ./test/OptimizerTests/monkey.jungle
  • test-mochanpx mocha --timeout 999999 build/mocha.cjs
  • test-optimizednpm run test-optimized-default && npm run test-optimized-with-forbidden
  • test-optimized-defaultnode test/test.js --showInfo --postOptimize --typeCheckLevel Strict --run-tests --product=fenix5 --product=fr235 --jungle ./test/OptimizerTests/monkey.jungle
  • test-optimized-with-forbiddennpm run test-optimized-default -- --allowForbiddenOpts
  • test-personalitynode test/test-personality.js
  • test-post-onlynode test/test.js --showInfo --typeCheckLevel Strict --skipOptimization --postOptimize --run-tests --product=fenix5 --product=fr235 --jungle ./test/OptimizerTests/monkey.jungle
  • test-remotenode ./test/test.js --showInfo --postOptimize --product=pick-one --ignore-settings-files --github
  • test-remote-testsnpm run test-remote-tests-default && npm run test-remote-tests-with-forbidden
  • test-remote-tests-defaultnpm run test-remote -- --run-tests
  • test-remote-tests-with-forbiddennpm run test-remote-tests-default -- --allowForbiddenOpts
  • test-tinynode test/test-tiny.js
  • test-unoptnode test/test.js --typeCheckLevel Strict --skipOptimization --run-tests --product=fenix5 --product=fr235 --jungle ./test/OptimizerTests/monkey.jungle
  • watchnode esbuild.mjs --watch
Dependencies2
  • 7z-wasm^1.2.0
  • @markw65/prettier-plugin-monkeyc^1.0.68