PkgRadar

npm · registry.npmjs.org

@loredotlink/cli

New Account With Lifecycle Hook: package first published 2 day(s) ago, 10 total version(s), has lifecycle hook

Why PkgRadar flagged 0.1.184

SeveritySignalEvidence
mediumNew Account With Lifecycle Hookpackage first published 2 day(s) ago, 10 total version(s), has lifecycle hook · package.json
mediumSuspicious Publish Context{"package_age_days":2,"publisher":"novelica","burst_same_day":2,"burst_week":2,"lure":null,"version_anomaly":false,"new_account":false}

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.184Review182026-06-20
0.1.183Review182026-06-20
0.1.188Review182026-06-20
0.1.189Review182026-06-20
0.1.187Review182026-06-20
0.1.182Review182026-06-20
0.1.180Review182026-06-20
0.1.181Review182026-06-20
0.1.186Review182026-06-19
0.1.185Review182026-06-19

Block this in CI

PkgRadar gates @loredotlink/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @loredotlink/[email protected]
@loredotlink/cli — npm security scan | PkgRadar