Static analysis flagged 16 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package source references child process execution.
app/assets/WorkerParser.jsView on unpkg · L53Package source references dynamic require/import behavior.
app/assets/esm-worker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/assets/ffmpeg-core.jsView on unpkg · L7Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
app/assets/index.jsView on unpkg · L1880Package contains source files above the normal full-analysis size ceiling.
server/WebServer.mjsView on unpkgPackage source references child process execution.
app/assets/WorkerParser.jsView on unpkg · L53Package source references dynamic require/import behavior.
app/assets/esm-worker.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/assets/ffmpeg-core.jsView on unpkg · L7Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
app/assets/index.jsView on unpkg · L1880Package contains source files above the normal full-analysis size ceiling.
server/WebServer.mjsView on unpkg