PkgRadar

npm · registry.npmjs.org

@elyracode/web-ui

Remote Dependency Spec: dependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz"

Why PkgRadar flagged 0.9.9

SeveritySignalEvidence
highRemote Dependency Specdependencies.xlsx="https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.9High risk82026-06-11
0.9.8High risk82026-06-10
0.9.7High risk82026-06-10
0.9.6High risk82026-06-10
0.9.5High risk82026-06-10
0.9.4High risk82026-06-10
0.9.3High risk82026-06-10
0.9.2High risk82026-06-10
0.9.1High risk122026-06-10
0.9.0High risk82026-06-10
0.8.3Review82026-05-28
0.8.4Review82026-05-28
0.8.1Review82026-05-27
0.8.0Review82026-05-27
0.7.16Review82026-05-26
0.7.15Review82026-05-25
0.7.14Review122026-05-25
0.7.13Review122026-05-25
0.7.12Review122026-05-24
0.7.11Review122026-05-24
0.7.9Review122026-05-24
0.7.10Review122026-05-24

Block this in CI

PkgRadar gates @elyracode/web-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @elyracode/[email protected]