Web
When opened in a browser and the user presses Publish, the package sends an npm bearer token and selected package contents to a third-party worker. This can expose publishing credentials and private source files.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page pre-fills an NPM Auth Token field with a credential-like npm token.
index.htmlView on unpkg · L80It base64-encodes every non-excluded entry from the selected ZIP and includes it in that request.
app.jsView on unpkg · L104This report applies to @vbansal67/npm-is-just-so-tuff@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page pre-fills an NPM Auth Token field with a credential-like npm token.
index.htmlView on unpkg · L80It base64-encodes every non-excluded entry from the selected ZIP and includes it in that request.
app.jsView on unpkg · L104