PkgRadar

npm · registry.npmjs.org

@n8n/n8n-benchmark

Remote Payload: matched "wget "

Why PkgRadar flagged 2.10.0

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · package/scripts/n8n-setups/postgres/docker-compose.yml
mediumRemote Payloadmatched "wget " · package/scripts/n8n-setups/scaling-multi-main/docker-compose.yml
mediumRemote Payloadmatched "wget " · package/scripts/n8n-setups/scaling-single-main/docker-compose.yml
mediumRemote Payloadmatched "wget " · package/scripts/n8n-setups/sqlite/docker-compose.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
2.11.0Low risk02026-06-09
1.30.7Low risk02026-06-01
2.10.0Review142026-05-27
1.30.6Review482026-05-25
2.9.0Review482026-05-25

Block this in CI

PkgRadar gates @n8n/n8n-benchmark (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @n8n/[email protected]