PkgRadar

npm · registry.npmjs.org

@axiomify/native

Remote Dependency Spec: optionalDependencies.uWebSockets.js="git+https://github.com/uNetworking/uWebSockets.js.git#v20.68.0"

Why PkgRadar flagged 6.3.2

SeveritySignalEvidence
highRemote Dependency SpecoptionalDependencies.uWebSockets.js="git+https://github.com/uNetworking/uWebSockets.js.git#v20.68.0" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
6.3.2High risk352026-06-10
6.3.1High risk352026-06-10
6.1.0High risk702026-06-10
6.3.0High risk702026-06-10
6.2.0High risk352026-06-10
6.0.0-rc.2Low risk02026-05-25
6.0.0Low risk02026-05-25

Related campaigns

Block this in CI

PkgRadar gates @axiomify/native (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @axiomify/[email protected]