PkgRadar

npm · registry.npmjs.org

@dimpozommy/create-mern-bonfils-exam

Credential File Packaged: package/templates/Humana-Resource-Management-System/backend/.env

Why PkgRadar flagged 2.0.4

SeveritySignalEvidence
highCredential File Packagedpackage/templates/Humana-Resource-Management-System/backend/.env · package/templates/Humana-Resource-Management-System/backend/.env
highCredential File Packagedpackage/templates/Humana-Resource-Management-System/frontend/.env · package/templates/Humana-Resource-Management-System/frontend/.env
highCredential File Packagedpackage/templates/project4/backend/.env · package/templates/project4/backend/.env
highCredential File Packagedpackage/templates/project4/frontend/.env · package/templates/project4/frontend/.env
highCredential File Packagedpackage/templates/SMS/IRASUBIZA_Bonfils_National_Practical_Exam_2026/backend/.env · package/templates/SMS/IRASUBIZA_Bonfils_National_Practical_Exam_2026/backend/.env
highCredential File Packagedpackage/templates/vrs/backend/.env · package/templates/vrs/backend/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.4High risk1002026-06-08
2.0.3High risk1002026-06-08
1.0.0Low risk02026-06-08
2.0.2High risk1002026-06-08

Block this in CI

PkgRadar gates @dimpozommy/create-mern-bonfils-exam (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dimpozommy/[email protected]