Web
On a user-initiated publish, the package sends an npm credential and selected package contents to a third-party Worker. The UI presents this as publishing to npm.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe request sends the entered npm bearer token to that Worker.
app.jsView on unpkg · L174Selected package files are base64 encoded and included in the same request.
app.jsView on unpkg · L126The browser path directs publishing to a package-author-controlled Worker rather than npm.
app.jsView on unpkg · L149This report applies to @vbansal67/not-again-bruh@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe request sends the entered npm bearer token to that Worker.
app.jsView on unpkg · L174Selected package files are base64 encoded and included in the same request.
app.jsView on unpkg · L126The browser path directs publishing to a package-author-controlled Worker rather than npm.
app.jsView on unpkg · L149