Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 65
- Versions published
- 37Mature · −50% score
- First published
- Mar 2019
- Publisher
- williambelle
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Large Javascript Payload: 4029719 bytes
1 remote tarball(s) were followed statically.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 14 · status changed
Evidence
Static findings
3 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Large Javascript Payload | package/dist/js/reader.js | 4029719 bytes | 10 |
| medium | Large Javascript Payload | package/dist/js/reader.min.js | 2673992 bytes | 10 |
| high | Remote Dependency Spec | package.json | devDependencies.colorable="https://github.com/epfl-si/colorable" | 8 |
Remote payloads
Followed remote artifacts
| Source | URL | Risk | Score | Summary |
|---|---|---|---|---|
| devDependencies.colorable | https://github.com/epfl-si/colorable | error | 0 | invalid gzip header |
Manifest
Package metadata
Scripts14
buildyarn distcleanrm -rf build/ dist/distwebpack --mode=productionlinteslint .realcleanrm -rf build/ dist/ node_modules/releaserelease-itstartwebpack --mode=development --watchstylelintstylelint '**/*.scss'test:approvebackstop approve --config=build/backstop.jsontest:changesbash -c ' backstop test --config=build/backstop.json "$@" ' --test:infonode scripts/backstop_status.jstest:preparebash -c ' set -e -x; install -d build; node scripts/make_backstop_json.js "$@" ' --test:referencebackstop reference --config=build/backstop.jsontest:reportbackstop openReport --config=build/backstop.json
Dependencies16
@selectize/selectize^0.13.6bootstrap^4.6.2clipboard^2.0.11cookieconsent^3.1.1feather-icons^4.29.0flickity2.2.2flickity-as-nav-for^2.0.1flickity-fullscreen^1.1.1imagesloaded^4.1.4intro.js^2.9.3jquery^3.7.1jquery-mousewheel^3.1.13multiple-select^2.2.0pickadate^3.6.4popper.js^1.16.1tablesaw^3.1.2