SafeDep
Install GitHub App

Summary

Missing project info alone is insufficient to label parse5 (7.3.0) as malware. Further investigation is required.

Verification Record

No verification record available.

Details

The available evidence only indicates a lack of readily available source project information for the parse5 package (version 7.3.0). This is insufficient to classify it as malware. The absence of project information could be due to several benign reasons: the project might be newly created, the repository might be private, or our database might lack the information. Without additional evidence such as suspicious code behavior identified by LLM analysis or YARA matches (even considering the limitations of YARA), or other indicators of malicious intent, we cannot conclude that this package is malicious. The low confidence level of the single evidence further supports this conclusion. More investigation is needed before any determination of maliciousness can be made.

parse5@7.3.0Clean
Unverified
Analysed at: 4/22/25, 5:10 PM
Source: https://registry.npmjs.org/parse5/-/parse5-7.3.0.tgz
SHA256: 9316ca7af41da9e85071b62b9605aa0a6aaeb0463f833c29e7a331e7898f0420
Confidence: Medium