PkgRadar

Package evidence

[email protected]

Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.2/xlsx-0.20.2.tgz"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
1,107Niche · −30% score
Versions published
868Mature · −50% score
First published
Feb 2016
Publisher
manueldelapenna

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Artifact bytes698,125
Previous version2.6.2
Published2026-05-04T14:22:52.173Z
SHA-25650679f0c8e90d2bd5b13cae391e6ec0577bb2106de118d177ffb71ab73922c66

Why flagged

What the scanner saw

Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.2/xlsx-0.20.2.tgz"

1 remote tarball(s) were followed statically.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
3Score
2.6.3Version
Status history (1 event)
  1. newavailable · risk review · score 3 · status changed

Evidence

Static findings

1 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highRemote Dependency Specpackage.jsondependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.2/xlsx-0.20.2.tgz"12

Remote payloads

Followed remote artifacts

SourceURLRiskScoreSummary
dependencies.xlsxhttps://cdn.sheetjs.com/xlsx-0.20.2/xlsx-0.20.2.tgzlow0no remote findings

Manifest

Package metadata

Scripts14
  • example-4testnode examples/4test/server/server-4test.js
  • example-fichasnode examples/fichero/server/server-fichas.js
  • example-punode test/puppeteer/first-step.js
  • example-tablesnode examples/tables/server/server-tables.js --dir-x examples/tables
  • prepublish(tsc -p tsconfig-server.json || echo "continue w/error") && (tsc -p tsconfig-client.json || echo "continue w/error")
  • server-testnode test/run-simple-backend.js
  • testecho testear SiPer que usa la mayoría de la funcionalidad de Backend-Plus
  • test-ci(npm run prepublish || echo "continue w/error") && mocha --reporter spec --bail test/test*.js
  • test-goodmocha --reporter spec --bail --check-leaks test/test*.js
  • test-karma(npm run prepublish || echo "continue w/error") && mocha --reporter spec --bail test/test-k*.js
  • test-punode ./test/download_puppeteer && mocha --reporter spec --bail --check-leaks --globals cptable --globals QUOTE --globals __core-js_shared__ test/test-pu.js
  • test-servermocha --reporter spec --single-run --bail test/test.js
  • test-ui(npm run prepublish || echo "continue w/error") && mocha --reporter spec --single-run --bail test/test-*.js
  • test-whynode --expose-internals ./node_modules/mocha/bin/_mocha --reporter spec --bail test/test*.js
Dependencies46
  • @upgraded/locate-path^6.0.0-alfa.1
  • ajax-best-promise^0.4.3
  • backend-skins^0.1.34
  • best-globals^2.1.0
  • big.js^7.0.1
  • body-parser^2.2.2
  • cast-error^0.1.3
  • castellano^0.1.5
  • connect-pg-simple^10.0.0
  • cookie-parser^1.4.7
  • cors^2.8.6
  • dialog-promise^0.10.5
  • discrepances^0.2.14
  • express^5.2.1
  • express-session^1.19.0
  • express-useragent^2.1.0
  • fs-extra^11.3.4
  • js-to-html^1.3.5
  • js-yaml^4.1.1
  • json4all^1.4.2
  • lazy-some^0.1.0
  • like-ar^0.5.2
  • login-plus^1.8.1
  • memorystore^1.6.8
  • mini-tools^1.13.5
  • moment^2.30.1
  • multiparty^4.2.3
  • nodemailer^8.0.7
  • numeral^2.0.6
  • pg-promise-strict^1.4.5
  • …and 16 more.