Web
Opening the HTML publisher and clicking Publish sends an NPM bearer token and selected package contents through an unaffiliated Cloudflare Worker. The bundled token makes credential compromise immediately actionable.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML pre-populates the NPM authentication-token field with a credential.
index.htmlView on unpkg · L81The selected archive or file is encoded and included in the same request payload.
app.jsView on unpkg · L123This report applies to @vbansal67/npm-publishinginginginginging@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML pre-populates the NPM authentication-token field with a credential.
index.htmlView on unpkg · L81The selected archive or file is encoded and included in the same request payload.
app.jsView on unpkg · L123