PkgRadar

npm · registry.npmjs.org

@guiho/xdocs

Native Binary Main Entry: main/bin entry points to a compiled binary: ./library/guiho-xdocs.js

Why PkgRadar flagged 0.3.0-alpha.1

SeveritySignalEvidence
highNative Binary Main Entrymain/bin entry points to a compiled binary: ./library/guiho-xdocs.js · package.json
highNew Lifecycle Script Vs Previouspostinstall added in 0.3.0-alpha.1 vs 0.2.3: "node ./scripts/install-native.cjs" · package.json
mediumNew Account With Lifecycle Hookpackage first published 8 day(s) ago, 7 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0-alpha.1High risk902026-06-10
0.2.3Low risk02026-06-09
0.2.2Low risk02026-06-07
0.2.1Low risk02026-06-07
0.1.2Low risk02026-06-02
0.1.3Low risk02026-06-02

Block this in CI

PkgRadar gates @guiho/xdocs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @guiho/[email protected]