PkgRadar

npm · registry.npmjs.org

@d0v3riz/baileys

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 7.0.0-rc14

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/lib/Utils/generics.js
mediumRemote Dependency Specdependencies.libsignal="github:d0v3riz/libsignal-node" · package.json
mediumDependency Changed To Remote Vs Previousdependencies.libsignal changed to remote spec in 7.0.0-rc14 vs 7.0.0-rc13: "github:d0v3riz/libsignal-node" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
7.0.0-rc14High risk412026-06-10
7.0.0-rc.9Review142026-05-30
7.0.0-rc13Review82026-05-30

Block this in CI

PkgRadar gates @d0v3riz/baileys (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @d0v3riz/[email protected]