Web
This browser publisher forwards npm bearer credentials and uploaded package contents to a third-party Worker during normal web use. It also persists the token locally.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page contains an embedded npm authentication token.
index.htmlView on unpkg · L79On a normal browser launch, the supplied token and uploaded package payload are sent to an unrelated Cloudflare Worker rather than npm.
app.jsView on unpkg · L149Selected file contents are base64-encoded and included in the outbound request.
app.jsView on unpkg · L126This report applies to @vbansal67/npm-is-so-tuff@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page contains an embedded npm authentication token.
index.htmlView on unpkg · L79On a normal browser launch, the supplied token and uploaded package payload are sent to an unrelated Cloudflare Worker rather than npm.
app.jsView on unpkg · L149Selected file contents are base64-encoded and included in the outbound request.
app.jsView on unpkg · L126