PkgRadar

npm · registry.npmjs.org

@hienlh/ppm

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.13.102

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/src/services/ppmbot/ppmbot-telegram.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/src/services/telegram-notification.service.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.13.102Review342026-06-08
0.13.99Review232026-06-08
0.13.97Review232026-06-07
0.13.94Review232026-06-06
0.13.95Review232026-06-06
0.13.93Review232026-06-02
0.13.92Review232026-06-02
0.13.90Review232026-06-01
0.13.91Review232026-06-01
0.13.89Review232026-05-31
0.13.88Review232026-05-29
0.13.85Review232026-05-29
0.13.87Review232026-05-29

Block this in CI

PkgRadar gates @hienlh/ppm (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hienlh/[email protected]