All wm-plugin-teach-me-widget versions
wm-plugin-teach-me-widget @21.0.31
Security testing test package
Maintainers
Risk Dispositions (2 applicable to this version, 0 other)
Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.
| Rule | Source | Disposition | Author | Reason | |
|---|---|---|---|---|---|
install-script:preinstall |
install-scripts | reject | AI | AI (install-scripts): Preinstall script on a self-described security-test package from a zero-history publisher; generalizes to all versions. | |
bogus-package |
bogus-package | reject | AI | AI (bogus-package): All bogus-package signals present; package is explicitly a test/probe artifact with no legitimate use. |
SAST Findings (3)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ossf-package-analysis (ebd46f9bf707420f68f24a52ca7bb9e517929d8e545802374dcb09697c8df410) The OpenSSF Package Analysis project identified 'wm-plugin-teach-me-widget' @ 21.0.31 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Script: node src/preinstall.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Review Summary
Risk score: 78. Findings: 1 critical (+40), 1 high (+25), 1 medium (+10), 1 low (+3).
Published to npm: