PkgRadar

Package evidence

[email protected]

Large Javascript Payload: 3777059 bytes

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
40,980Mainstream · −50% score
Versions published
181Mature · −50% score
First published
Feb 2021
Publisher
alekseymanetov

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Artifact bytes5,652,347
Previous version5.26.1
Published2026-04-27T15:32:52.792Z
SHA-25601efdc236d4db41e58e66ad83641e6611df267574632da1ee592ca7a17e60da9

Why flagged

What the scanner saw

Large Javascript Payload: 3777059 bytes

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
25Score
5.27.0Version
Status history (1 event)
  1. newavailable · risk review · score 25 · status changed

Evidence

Static findings

5 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumLarge Javascript Payloadpackage/dist/base-modeler.development.js3777059 bytes10
mediumLarge Javascript Payloadpackage/dist/camunda-cloud-modeler.development.js5657839 bytes10
mediumLarge Javascript Payloadpackage/dist/camunda-cloud-modeler.production.min.js2464722 bytes10
mediumLarge Javascript Payloadpackage/dist/camunda-platform-modeler.development.js5445114 bytes10
mediumLarge Javascript Payloadpackage/dist/camunda-platform-modeler.production.min.js2401122 bytes10

Manifest

Package metadata

Scripts22
  • allrun-s clean lint test generate-types distro test:distro
  • cleandel-cli dist
  • devnpm test -- --auto-watch --no-single-run
  • distrorollup -c --failAfterWarnings
  • formatrun-s format:markdown 'lint -- --fix'
  • format:markdownremark . -qo
  • generate-typesrun-s generate-types:*
  • generate-types:generatedel-cli "lib/**/*.d.ts" && bio-dts -r --resolveJsonModule --esModuleInterop lib
  • generate-types:testtsc --noEmit
  • linteslint .
  • preparerun-s clean distro
  • prepublishOnlyrun-s generate-types test:distro
  • startnpm run start:cloud
  • start:basecross-env SINGLE_START=base-modeler npm run dev
  • start:cloudcross-env SINGLE_START=camunda-cloud-modeler npm run dev
  • start:cloud-navigated-viewercross-env SINGLE_START=camunda-cloud-navigated-viewer npm run dev
  • start:cloud-viewercross-env SINGLE_START=camunda-cloud-viewer npm run dev
  • start:platformcross-env SINGLE_START=camunda-platform-modeler npm run dev
  • start:platform-navigated-viewercross-env SINGLE_START=camunda-platform-navigated-viewer npm run dev
  • start:platform-viewercross-env SINGLE_START=camunda-platform-viewer npm run dev
  • testkarma start karma.config.js
  • test:distronode tasks/test-distro.mjs
Dependencies22
  • @bpmn-io/align-to-origin^0.7.0
  • @bpmn-io/element-template-chooser^2.1.0
  • @bpmn-io/element-template-icon-renderer^1.0.0
  • @bpmn-io/properties-panel^3.41.2
  • @bpmn-io/variable-resolver^3.0.1
  • @camunda/example-data-properties-provider^1.4.0
  • bpmn-js^18.15.0
  • bpmn-js-color-picker^0.7.2
  • bpmn-js-copy-as-image^0.4.1
  • bpmn-js-create-append-anything^1.2.0
  • bpmn-js-element-templates^2.24.0
  • bpmn-js-executable-fix^0.2.1
  • bpmn-js-native-copy-paste^0.3.0
  • camunda-bpmn-js-behaviors^1.14.1
  • camunda-bpmn-moddle^7.0.1
  • diagram-js^15.13.0
  • diagram-js-grid^2.0.1
  • diagram-js-minimap^5.3.0
  • diagram-js-origin^1.4.0
  • inherits-browser^0.1.0
  • min-dash^5.0.0
  • zeebe-bpmn-moddle^1.13.0