Web
When the user clicks Publish, the browser sends their npm bearer token and selected package contents to a third-party Worker. The displayed publishing flow presents this as npm publishing, but browser mode selects the Worker endpoint.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML loads the publishing script in the package interface.
index.htmlView on unpkg · L104Browser-mode publishing sends the package payload to a third-party Worker instead of npm.
app.jsView on unpkg · L149The request forwards the entered npm bearer token and the complete encoded upload to that Worker.
app.jsView on unpkg · L171The app persists the entered npm token in browser local storage.
app.jsView on unpkg · L6This report applies to @vbansal67/final-npm-uploader@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML loads the publishing script in the package interface.
index.htmlView on unpkg · L104Browser-mode publishing sends the package payload to a third-party Worker instead of npm.
app.jsView on unpkg · L149The request forwards the entered npm bearer token and the complete encoded upload to that Worker.
app.jsView on unpkg · L171The app persists the entered npm token in browser local storage.
app.jsView on unpkg · L6