Web
When a user publishes from a browser, the package sends their NPM bearer token and selected package data to a third-party Worker. The Worker is not the NPM registry and can receive both credentials and uploaded contents.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page saves NPM authentication tokens in browser local storage.
app.jsView on unpkg · L6Browser use routes publishing through an unrelated Cloudflare Worker instead of the NPM registry.
app.jsView on unpkg · L173The request sends the bearer token and uploaded package payload to that Worker.
app.jsView on unpkg · L194Selected ZIP contents are base64 encoded into the transmitted payload.
app.jsView on unpkg · L142This report applies to @vbansal67/npm-publishing@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page saves NPM authentication tokens in browser local storage.
app.jsView on unpkg · L6Browser use routes publishing through an unrelated Cloudflare Worker instead of the NPM registry.
app.jsView on unpkg · L173The request sends the bearer token and uploaded package payload to that Worker.
app.jsView on unpkg · L194Selected ZIP contents are base64 encoded into the transmitted payload.
app.jsView on unpkg · L142