Checksum.ai test runtime
Static analysis flagged 19 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
checksumlib.jsView on unpkg · L74Package source references weak cryptographic algorithms.
scripts/playwright_patches/1.52.0.jsView on unpkg · L294Package contains source files above the normal full-analysis size ceiling.
index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkgHardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44This report applies to @checksum-ai/runtime@4.12.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
postinstall.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
postinstall.jsView on unpkg · L30Package source references a known benign dynamic code generation pattern.
checksumlib.jsView on unpkg · L74Package contains source files above the normal full-analysis size ceiling.
index.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
cli.jsView on unpkgPackage source references weak cryptographic algorithms.
scripts/playwright_patches/1.52.0.jsView on unpkg · L294Hardcoded password in checksum-root/checksum.config.ts
checksum-root/checksum.config.tsView on unpkg · L44