npm package report

Is webpack-sources safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/webpack-sources
npm packagelast checked 2026-09-19

webpack-sources · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 18 graph-tracked dependencies · provenance: verified (sigstore)

Re-check live →

SIGNALS
Commit-Level AnalysisclearOK

4 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

Anomaly HistoryclearOK

1 historical anomaly alert(s) (maintainer_change) on this package. Add a version to check whether it is affected.

DEPENDENCIES
beautify-lint@^1.0.3clean
codecov.io@^0.1.6clean
coveralls@^2.11.6clean
eslint@^1.1.0clean
eslint-config-prettier@^3.5.0clean
eslint-plugin-jest@^23.20.0clean
eslint-plugin-mocha@^5.2.1clean
eslint-plugin-node@^11.1.0clean
eslint-plugin-nodeca@^1.0.3clean
eslint-plugin-prettier@^3.0.1clean
istanbul@^0.4.1clean
jest@^26.4.0clean
js-beautify@^1.5.10clean
mocha@^2.3.4clean
prettier@^1.15.3clean
should@^11.2.1clean
source-list-map@~0.1.0clean
source-map@~0.5.3clean
PACKAGE webpack-sourcesECOSYSTEM npmDECISION ALLOW

Package facts

Weekly downloads
254.4M
Centrality tier
tier 1
Build provenance
verified (sigstore)
Direct dependencies
18

Baked snapshot · run a live check for the current verdict · browse all packages

Other package reports

whichwinstonwswebpack-dev-serverwebpack-dev-middlewarewebpack-cli

See all package reports or check any package live.