CLI for configuring and building React Native projects
Static analysis completed at 97.0% confidence. No malicious behavior was detected; 12 low-signal pattern(s) were surfaced and cleared.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/checks/java.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/checks/java.jsView on unpkgPackage source references dynamic require/import behavior.
src/checks/java.jsView on unpkg · L1Package source invokes a package manager install command at runtime.
src/expo/maps.jsView on unpkg · L22This report applies to mapfix@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
src/checks/java.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/checks/java.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/checks/java.jsView on unpkgPackage source invokes a package manager install command at runtime.
src/expo/maps.jsView on unpkg · L22