Loading npm security reports…
No confirmed malicious attack surface. The package is a browser UI library with static component exports; the flagged Unicode is a comment character in bundled editor dependency code.
Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/RichTextEditor-B4ZPAevY.jsView on unpkg · L2105A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/RichTextEditor-B4ZPAevY.jsView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/RichTextEditor-B4ZPAevY.jsView on unpkg · L2105A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/RichTextEditor-B4ZPAevY.jsView on unpkg