Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 1,238Niche · −30% score
- Versions published
- 373Mature · −50% score
- First published
- Jun 2023
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 12184227 bytes
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 3 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/axitech-widget.umd.js | 12184227 bytes | 10 |
Manifest
Package metadata
Scripts14
buildrimraf dist && vue-tsc && vite buildconvert-svgnode cli-utils/convert-svg-to-vue.jsdocs:buildnpm run generate --prefix docsdocs:devnpx dotenv-cli -e .env -- npx vitepress dev docs-local --hostdocs:installnpm install --prefix docsdocs:local-devnpx dotenv-cli -e .env -- npm run dev --prefix docsdocs:servenpx vitepress serve docslinteslint --fix ./preparehuskypubnpm version patch --force && npm publishtypecheckvue-tsc --noEmitupgrade:betaexport VERSION=$(npm view axitech-widget version --tag beta) && echo $VERSION && npm install axitech-widget@$VERSION --prefix docsupgrade:latestexport VERSION=$(npm view axitech-widget version --tag latest) && echo $VERSION && npm install axitech-widget@$VERSION --prefix docsupgrade:stagingexport VERSION=$(npm view axitech-widget version --tag staging) && echo $VERSION && npm install axitech-widget@$VERSION --prefix docs
Dependencies30
@aws-sdk/client-s3^3.1043.0@googlemaps/js-api-loader^1.16.10@jsonforms/core3.7.0@jsonforms/vue3.7.0@jsonforms/vue-vanilla3.7.0@openreplay/tracker^16.4.1@openreplay/tracker-assist^11.0.15@sentry/vue^8.55.2@uppy/aws-s3^4.3.2@uppy/compressor^2.3.2@uppy/core^4.5.3@uppy/dashboard^4.4.3@uppy/drag-drop^4.2.2@uppy/drop-target^3.2.2@uppy/file-input^4.2.2@uppy/progress-bar^4.3.2@uppy/thumbnail-generator^4.2.3@uppy/utils^6.2.2@uppy/vue^2.4.2@vueuse/core^13.9.0ajv^8.18.0ajv-errors^3.0.0class-variance-authority^0.7.1dayjs^1.11.20floating-vue^5.2.2libphonenumber-js^1.13.3posthog-js^1.376.0tailwind-merge^2.6.1ua-parser-js^2.0.9vue-tel-input9.8.0