No attack surface was identified in the inspected package.
Package source references a known benign dynamic code generation pattern.
script.jsView on unpkg · L3The entrypoint decodes a fixed Base64 string for console.log('hello world') and evaluates it; no network, file, credential, or process behavior is present.
script.jsView on unpkg · L2The package declares script.js as its main entrypoint and has no lifecycle scripts.
package.jsonView on unpkg · L5This report applies to npmscript_tesstalert_unpkg@1.1.6.
See version security history for other recorded verdicts.
Evidence last updated: .
The entrypoint decodes a fixed Base64 string for console.log('hello world') and evaluates it; no network, file, credential, or process behavior is present.
script.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
script.jsView on unpkg · L3The package declares script.js as its main entrypoint and has no lifecycle scripts.
package.jsonView on unpkg · L5