PkgRadar

npm · registry.npmjs.org

@hexclave/cli

Credential File Packaged: package/dist/dashboard/apps/dashboard/.env

Why PkgRadar flagged 1.0.6

SeveritySignalEvidence
highCredential File Packagedpackage/dist/dashboard/apps/dashboard/.env · package/dist/dashboard/apps/dashboard/.env
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/dist/dashboard/apps/dashboard/node_modules/next/dist/lib/mkcert.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.6Review142026-06-05
1.0.5Review142026-06-05

Block this in CI

PkgRadar gates @hexclave/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hexclave/[email protected]