npm · registry.npmjs.org
@crysnovax/baileys
Remote Dependency Spec: dependencies.libsignal="github:WhiskeySockets/libsignal-wasm#master"
Why PkgRadar flagged 2.5.6
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Dependency Spec | dependencies.libsignal="github:WhiskeySockets/libsignal-wasm#master" · package.json |
| medium | Dependency Changed To Remote Vs Previous | dependencies.libsignal changed to remote spec in 2.5.6 vs 2.5.5: "github:WhiskeySockets/libsignal-wasm#master" · package.json |
| medium | New Account With Lifecycle Hook | package first published 34 day(s) ago, 7 total version(s), has lifecycle hook · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.5.6 | High risk | 29 | 2026-06-09 |
2.5.5 | Review | 5 | 2026-06-09 |
1.0.4 | High risk | 17 | 2026-06-09 |
2.0.0 | High risk | 17 | 2026-06-09 |
2.5.0 | High risk | 17 | 2026-06-09 |
2.5.2 | Review | 5 | 2026-06-09 |
Block this in CI
pkgradar gate --ecosystem npm @crysnovax/[email protected]