Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 7,160Mature · −50% score
- First published
- Apr 2021
- Publisher
- nikunj1729
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@zeniai/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@zeniai/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 8247159 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
4 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 4 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Large Javascript Payload | package/dist/SessionTimeoutPopup-NlWl1fK9.cjs | 8247159 bytes | 0 |
| low | Large Javascript Payload | package/dist/vendor-.pnpm-BFaLhzCH.cjs | 2030121 bytes | 0 |
| low | Large Javascript Payload | package/dist/SessionTimeoutPopup-DWMg30kR.js | 10885328 bytes | 0 |
| low | Large Javascript Payload | package/dist/vendor-.pnpm-BcaysHV_.js | 2988926 bytes | 0 |
Manifest
Package metadata
Scripts41
analyzevite-bundle-visualizer -t sunburstbuildexport NODE_OPTIONS=--max-old-space-size=8192 && pnpm lint-modified-files && pnpm tsc-modified-files && vite buildbuild-betaexport NODE_OPTIONS=--max-old-space-size=8192 && tsc && vite build --config vite.dev.config.ts && ([ -f dist/web-components.css ] && mv dist/web-components.css dist/index.css || true)build-beta-and-copychmod +x ./scripts/build_and_copy.sh && ./scripts/build_and_copy.shbuild-storiesexport NODE_OPTIONS=--max-old-space-size=8192 && tsc --noEmitbuild-storybookexport NODE_OPTIONS=--max-old-space-size=8192 && storybook buildbump-update-web-app-cockpit-betachmod +x ./scripts/bump_and_update_web_app_ui_beta.sh && ./scripts/bump_and_update_web_app_ui_beta.shcheck-dependenciesnode ./scripts/check_dependencies.jscheck-versionnode ./scripts/check_version.jscherry-pickchmod +x ./scripts/cherry_pick.sh && ./scripts/cherry_pick.shchromaticnpx chromatic --project-token=b0f981300c3c --auto-accept-changescircular-dependencynpx madge --circular --extensions ts ./srccleanrimraf buildclean-overridesnode ./scripts/clean_overrides.jsdata-testid-changeschmod +x ./scripts/data-testid-changes.sh && ./scripts/data-testid-changes.shfind-dead-codets-prune | grep -v '(used in module)'find-unused-exportsts-unused-exports ./tsconfig.jsonformatprettier --write --ignore-unknown "src/**/*" && pnpm lintformat-stagedgit diff --cached --name-only --diff-filter=ACM | grep -E '\.(ts|tsx|js)$' | xargs prettier --write || trueformat-watch(git diff --name-only --diff-filter=ACM && git ls-files --others --exclude-standard) | grep -E '\.(ts|tsx|js)$' | xargs prettier --write || truelintexport NODE_OPTIONS=--max-old-space-size=8192 && time eslint src --ext ts,tsx --report-unused-disable-directives --max-warnings 0 --fixlint-modified-fileschmod +x ./scripts/lint-modified-files.sh && ./scripts/lint-modified-files.shlint:fixchmod +x ./scripts/fix-lint.sh && ./scripts/fix-lint.shlint:fix-modified-fileschmod +x ./scripts/lint-modified-files.sh && LINT_FIX=true ./scripts/lint-modified-files.shpostversiongit push && git push --tagsprebuildnode ./scripts/check-imports.jspreviewvite previewpublish-betash -c 'echo "Publishing with tag: ${betaTag:-beta}" && pnpm publish --tag ${betaTag:-beta} --no-git-checks'raise-pr-automationchmod +x ./scripts/raise_pr_automation.sh && ./scripts/raise_pr_automation.shstorybookexport NODE_OPTIONS=--max-old-space-size=8192 && storybook dev -p 6006- …and 11 more.
Dependencies71
@babel/runtime^7.26.10@emotion/cache^11.13.1@emotion/react11.10.0@emotion/styled11.10.0@lexical/code^0.9.1@lexical/html^0.9.1@lexical/link^0.9.1@lexical/list^0.9.1@lexical/markdown^0.9.1@lexical/react^0.9.1@lexical/rich-text^0.9.1@lexical/selection^0.9.1@lexical/table^0.9.1@lexical/utils^0.9.1@liveblocks/react^2.23.0@liveblocks/react-ui^2.23.0@mui/material^7.3.5@react-oauth/google^0.12.2@sentry/core^9.42.1@sentry/react^9.42.1@statsig/react-bindings^3.14.0@stripe/react-stripe-js^2.7.3@stripe/stripe-js^4.4.0@zeniai/client-analytics2.0.28@zeniai/client-epic-state5.1.18-betaRD1autosuggest-highlight^3.2.1browser-image-compression^2.0.2countries-list^2.6.1country-flag-icons^1.5.5cross-fetch^3.1.5- …and 41 more.