PkgRadar

npm · registry.npmjs.org

@nextsparkjs/core

Install Lifecycle Suppresses Failure: postinstall="node scripts/postinstall.mjs || true"

Why PkgRadar flagged 0.1.0-beta.167

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="node scripts/postinstall.mjs || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.0-beta.167High risk172026-06-15
0.1.0-beta.166High risk172026-06-10
0.1.0-beta.164High risk172026-06-10
0.1.0-beta.163High risk172026-06-10
0.1.0-beta.155High risk172026-06-10
0.1.0-beta.154High risk172026-06-10
0.1.0-beta.153High risk172026-06-10
0.1.0-beta.162High risk172026-06-10
0.1.0-beta.161High risk252026-06-10
0.1.0-beta.160High risk252026-06-10
0.1.0-beta.159High risk172026-06-10
0.1.0-beta.158High risk252026-06-10
0.1.0-beta.157High risk172026-06-10
0.1.0-beta.156High risk172026-06-10

Block this in CI

PkgRadar gates @nextsparkjs/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nextsparkjs/[email protected]
@nextsparkjs/core — npm security scan | PkgRadar