npm
An extremely fast JavaScript and CSS bundler and minifier.
Public repositories of contributors | 2,100 |
Followers of contributors | 140,000 |
Repository forks | 1,150 |
Open issues | 455 |
Repository watchers | 277 |
Number of contributors | 109 |
Repository stars | 38,100 |
Package has a historical provenance match, confirming its source of origin.
Typosquatting is the risk of installing a malicious package that uses a name similar to a legitimate one.
Starjacking can mislead users into trusting a package, hiding malicious code behind inflated popularity.