Holder uses CANVAS to render image placeholders entirely in browser.
Do not install. Package is flagged as malicious (advisory MAL-2025-29354).
MAL-2025-29354 — Malicious code in placeHolder.js (npm)Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/placeholder.jsFirst published · 2015-12-21T08:50:54.778Z
Last updated · 2016-06-13T05:28:06.874Z