82OUT OF 100
Likely safeLikely safeStatic read

npm/Hello

The package 'Hello@0.0.1' is a legacy artifact from 2016 with no documented purpose, no README, and no linked source repository. While the static scan found no malicious code, the lack of transparency and the extremely low download volume warrant caution. Full runtime behavior was not executed in a sandbox on this pass.

Repository size
0 KB
Packages
0
Stars
—
Created
2016-06-03
Reputation signals
npm avatar
Hello
npm package
Code & behavior signals
Lack of Documentation
LowReputation

The package has no README and no declared source repository, making its intent impossible to verify.

Low Activity/Visibility
LowReputation

The package has minimal downloads and no community presence, which is common for abandoned or placeholder packages.

Per-package scoring
Final verdict

No malicious behavior in our static read. The caveats above are worth noting and the owner is not yet long-established. Runtime was not executed in a sandbox on this pass.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Fetched npm tarball for Hello@0.0.1
›Integrity verified via sha512
Static scan
›No flagged regions detected
›No install hooks found
Reputation
›Package is 8 years old but has no documentation
›No linked source repository found
Read
›README is empty or missing
›Package intent is unknown
Score
›Score computed by formula: 82/100 (deterministic, code-driven)
Auto-published at clauderabbit.in/npm/Hello · re-checked when the package changes