PkgRadar

npm · registry.npmjs.org

@develop-plugins/vite-plugin-git-tag

Install-time lifecycle script: preinstall="node ./check-node-version.js"

Why PkgRadar flagged 0.9.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspreinstall added in 0.9.0 vs 0.8.0: "node ./check-node-version.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.0High risk452026-06-04
0.7.0High risk452026-06-04
0.8.0Review52026-06-04
0.6.0Low risk02026-05-26
0.5.0Low risk02026-05-26
0.4.0Low risk02026-05-26
0.3.0Low risk02026-05-25
0.2.0Low risk02026-05-25
0.1.0Low risk02026-05-25

Block this in CI

PkgRadar gates @develop-plugins/vite-plugin-git-tag (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @develop-plugins/[email protected]