registry  /  @vielzeug/refine  /  1.1.1

@vielzeug/refine@1.1.1

Accessible, themeable web components built on Ore custom element primitives

Static Scan Results

scanned 3h ago · by rust-scanner

Static analysis flagged 6 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcess
Supply chain
HighEntropyStringsMinifiedUrlStrings
Manifest
NoLicense
scanned 430 file(s), 2.66 MB of source, external domains: www.w3.org

Source & flagged code

1 flagged · loading source
dist/styles/mixins/animation.css.cjsView file
1package = @vielzeug/refine; repositoryIdentity = vielzeug; dependency = @vielzeug/ore L1: let e=require("@vielzeug/ore");var t=!1;function n(){if(!t){if(typeof CSS<`u`&&CSS.registerProperty)try{CSS.registerProperty({inherits:!1,initialValue:`0deg`,name:`--rainbow-angle`... L2: /* ========================================
High
Copied Package Dependency Bridge

Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.

dist/styles/mixins/animation.css.cjsView on unpkg · L1

Findings

1 High1 Medium4 Low
HighCopied Package Dependency Bridgedist/styles/mixins/animation.css.cjs
MediumStructural Risk Force Deep Review
LowScripts Present
LowHigh Entropy Strings
LowUrl Strings
LowNo License