DEV Community

Discussion on: How I exploited NPM downloads... and why you shouldn't trust them

Collapse
 
sqlrob profile image
Robert Myers

You don't need a significant portion to spoof for the metric to be useless.

Let's say you need a package, you go look at exxpress. It has 30M downloads, therefore it's probably the popular package you wanted. So you're good to go with npm install exxpress right?