Whether a shared package unfurls depends on which crawlers Cloudflare lets through today.
This is cause 1 of the 5 ways link previews break. The full breakdown covers the manual fix and the automatic one.
GET npmjs.com/package/express → 'Just a moment…' interstitialthe page title crawlers see is Cloudflare's, not the package'scards below render without touching npmjs.comPackage pages are JavaScript's reference library. Links that can't unfurl make the canonical source look less legitimate than a random blog covering the same package.
A package author has zero control over npm's WAF. Their launch posts inherit whatever the wall does that day.
With millions of packages, nobody at npm is testing how each one unfurls. Blocked crawlers fail silently at registry scale.
The link from a release announcement.
Cloudflare can allowlist verified bots. Preview crawlers are a category in its own settings; letting them through is a toggle, not a rebuild.
No team pastes millions of package links into chats to check them. Monitoring crawler access is the only way to see this class of failure.
OpenGraph+ renders and hosts the card image, so the preview resolves from a domain the WAF isn't guarding.