Web
A user clicking Publish sends an npm bearer token and selected package contents to a third-party Worker in browser mode. The page also contains a prefilled npm credential and stores entered tokens locally.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML prepopulates an npm password field with a credential.
index.htmlView on unpkg · L79Browser use redirects publishing to a custom Worker rather than the npm registry.
app.jsView on unpkg · L149The Worker request includes the bearer token and the complete uploaded package payload.
app.jsView on unpkg · L171The Worker request includes the bearer token and the complete uploaded package payload.
app.jsView on unpkg · L126This report applies to @vbansal67/npm-is-tuff@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML prepopulates an npm password field with a credential.
index.htmlView on unpkg · L79Browser use redirects publishing to a custom Worker rather than the npm registry.
app.jsView on unpkg · L149The Worker request includes the bearer token and the complete uploaded package payload.
app.jsView on unpkg · L171The Worker request includes the bearer token and the complete uploaded package payload.
app.jsView on unpkg · L126