Web
The browser publisher routes npm bearer credentials and selected package contents to a third-party Worker in normal web use. A credential is embedded in the page.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page embeds an npm authentication token as the password input’s default value.
index.htmlView on unpkg · L81Browser publishing sends the bearer token to a non-npm Worker endpoint.
app.jsView on unpkg · L183This report applies to @vbansal67/npm-is-tuff-bruh@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page embeds an npm authentication token as the password input’s default value.
index.htmlView on unpkg · L81Browser publishing sends the bearer token to a non-npm Worker endpoint.
app.jsView on unpkg · L183