PkgRadar

npm · registry.npmjs.org

@open-mercato/gateway-stripe

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 0.6.6-canary.5490.1.3b940bdc47

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/modules/gateway_stripe/webhook-guide.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/src/modules/gateway_stripe/webhook-guide.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.6-canary.5490.1.3b940bdc47High risk252026-06-13
0.6.6-canary.5492.1.1e56e4bfabHigh risk252026-06-13
0.6.6-canary.5489.1.725103a93eHigh risk502026-06-13
0.6.6-develop.5491.1.469e89d368High risk502026-06-13
0.6.6-canary.5486.1.930a936cebHigh risk252026-06-13
0.6.6-canary.5485.1.e494bca2b7High risk502026-06-13
0.6.6-develop.5483.1.a1129165eaHigh risk502026-06-13
0.6.6-canary.5484.1.68a7662794High risk502026-06-13
0.6.6-canary.5482.1.467a24ace7High risk252026-06-13
0.6.6-canary.5470.1.0fcae0baa8High risk502026-06-12
0.6.6-canary.5469.1.12922dda29High risk252026-06-12
0.6.6-canary.5460.1.b790700e24High risk252026-06-11
0.6.6-develop.5459.1.170077434eHigh risk502026-06-11
0.6.6-canary.5444.1.772518065bHigh risk502026-06-11
0.6.6-canary.5442.1.46a60acdebHigh risk252026-06-11
0.6.6-canary.5440.1.cf9e492ca5High risk502026-06-11
0.6.6-canary.5438.1.be6ac2bf3bHigh risk502026-06-11
0.6.6-canary.5437.1.53c414d811High risk252026-06-11
0.6.6-canary.5432.1.1ad1db5903High risk502026-06-11
0.6.6-canary.5430.1.36c322c0c8High risk502026-06-11
0.6.6-develop.5431.1.384a97c7a2High risk502026-06-11
0.6.6-canary.5429.1.933a8cde6aHigh risk502026-06-11
0.6.6-canary.5422.1.5cfb5c42e5High risk252026-06-11
0.6.6-canary.5413.1.341393a259High risk502026-06-11
0.6.5-canary.5406.1.957816a51cHigh risk502026-06-11
0.6.6-develop.5412.1.e2a52b14f0High risk502026-06-11
0.6.5-canary.5407.1.d888dd7e41High risk502026-06-11
0.6.5-canary.5385.1.1bc2e1724cHigh risk502026-06-11
0.6.5-develop.5382.1.f542de69afHigh risk502026-06-11
0.6.5-canary.5272.2.872223b814High risk502026-06-11
0.6.5-canary.5356.1.59ca80eaa7High risk502026-06-11
0.6.5-canary.5357.1.d6f39da21aHigh risk502026-06-11
0.6.5-develop.5337.1.534b781eacHigh risk502026-06-11
0.6.5-canary.5338.1.8e686edcfcHigh risk502026-06-11
0.6.5-canary.5336.1.27024905b6High risk502026-06-11
0.6.5-canary.5335.1.d13e73ea25High risk252026-06-11
0.6.5-canary.5330.1.a1196db607High risk502026-06-10
0.6.5-canary.5331.1.e0c8f54f73High risk502026-06-10
0.6.5-canary.5329.1.ad1a9ce1a9High risk502026-06-10
0.6.5-canary.5323.1.6e173ccfbcHigh risk252026-06-10
0.6.5-canary.5322.1.870f4fd4bfHigh risk502026-06-10
0.6.5-develop.5309.1.be1df535b3High risk502026-06-10
0.6.5-canary.5310.1.2d4198c7eeHigh risk502026-06-10
0.6.5-canary.5306.1.26b1ca5c52High risk502026-06-10
0.6.5-canary.5297.1.fa046483e1High risk502026-06-10
0.6.5-develop.5296.1.799a610136High risk502026-06-10
0.6.4-canary.3993.1.739a4e21a9High risk252026-06-10
0.6.4-canary.3992.1.0f76b3b18eHigh risk252026-06-10
0.6.3-canary.3903.1.13eab72bd2High risk252026-06-10
0.6.3-canary.3904.1.273b108254High risk252026-06-10
0.6.3-canary.3897.1.ceb161eecdHigh risk252026-06-10
0.6.3-canary.3898.1.6da7af2e8fHigh risk252026-06-10
0.6.3-canary.3801.1.c7e84192a4High risk502026-06-10
0.6.3-develop.3798.1.39325a8896High risk502026-06-10
0.6.3-canary.3781.1.683199a6deHigh risk252026-06-10
0.6.3-canary.3783.1.3ffdecef88High risk252026-06-10
0.6.3-develop.3766.1.33102bfc91High risk252026-06-10
0.6.3-canary.3768.1.92dd46fa07High risk252026-06-10
0.6.3-canary.3758.1.7aa00229abHigh risk252026-06-10
0.6.3-canary.3756.1.464f04b4fdHigh risk252026-06-10
0.6.3-develop.3755.1.84e4410d84High risk252026-06-10
0.6.3-canary.3757.1.210328791dHigh risk252026-06-10
0.6.3-canary.3754.1.115166578eHigh risk252026-06-10
0.6.3-develop.3753.1.29e9a20ddeHigh risk252026-06-10
0.6.3-canary.3752.1.c68cf3eca2High risk252026-06-10
0.6.3-canary.3750.1.111f2aba26High risk252026-06-10
0.6.3-canary.3749.1.4c42c72bc4High risk252026-06-10
0.6.3-canary.3748.1.4d27a7ee0cHigh risk252026-06-10
0.6.3-canary.3746.1.4fb8f8fd55High risk252026-06-10
0.6.5-canary.5291.1.1979409f69High risk502026-06-10
0.6.5-canary.5292.1.3d2752de28High risk502026-06-10
0.6.5-canary.5288.1.a116e9dcbaHigh risk502026-06-10
0.6.5-canary.5289.1.8b1b4e2e67High risk502026-06-10
0.6.5-canary.5286.1.5fe107a6ecHigh risk502026-06-10
0.6.5-develop.5285.1.e5c8c48406High risk502026-06-10
0.6.5-canary.5281.1.8f229c0fbaHigh risk252026-06-10
0.6.5-canary.5278.1.f8097b40c2High risk252026-06-10
0.6.5-canary.5257.2.a53e0e57bbHigh risk252026-06-10
0.6.5-develop.5266.2.9acdca82ecHigh risk502026-06-10
0.6.5-canary.5276.1.faedf9be6dHigh risk252026-06-10
0.6.5-canary.5275.1.c91dfe82b0High risk502026-06-10
0.6.5-canary.5273.1.f3c64d5002High risk502026-06-10
0.6.5-canary.5274.1.8671ad0bc7High risk252026-06-10
0.6.5-canary.5267.1.ef73241aa5High risk252026-06-10
0.6.5-canary.5270.1.a3e27fd7a4High risk252026-06-10
0.6.5-develop.5266.1.9acdca82ecHigh risk502026-06-10
0.6.5-canary.5272.1.872223b814High risk252026-06-10
0.6.5-canary.5261.1.70fbb3be9cHigh risk252026-06-10
0.6.5-canary.5257.1.a53e0e57bbHigh risk502026-06-10
0.6.5-canary.5269.1.583a90f8b5High risk502026-06-10
0.6.5-canary.5259.1.4b389970b7High risk502026-06-10
0.6.5-canary.5263.1.d4d644afcfHigh risk502026-06-10
0.6.5-canary.5258.1.bf02888169High risk502026-06-10
0.6.5-canary.5260.1.94f0db7a6aHigh risk502026-06-10
0.6.5-canary.5225.3.252ec55eb3High risk252026-06-10
0.6.5-canary.5239.2.011bfe8cc2High risk252026-06-10
0.6.5-develop.5240.2.bbd9d30275High risk252026-06-10
0.6.5-canary.5235.3.176c83e47fHigh risk252026-06-10
0.6.5-canary.5233.3.c08c6c4579High risk252026-06-10
0.6.5-canary.5254.1.07b5b0cdf9High risk252026-06-10
0.6.5-canary.5253.1.c442821df5High risk252026-06-10
0.6.5-canary.5255.1.81f4b7660eHigh risk252026-06-10
0.6.5-canary.5256.1.ec16dde9b3High risk252026-06-10
0.6.5-canary.5252.1.9d86014eeaHigh risk502026-06-10
0.6.5-canary.5251.1.223649fc97High risk252026-06-10
0.6.5-canary.5250.1.efe6f2d6fbHigh risk252026-06-10
0.6.5-canary.5249.1.6302919d8cHigh risk502026-06-10
0.6.5-canary.5248.1.e2d33b52d4High risk502026-06-10
0.6.5-canary.5244.1.9da1064b6dHigh risk502026-06-10
0.6.5-canary.5246.1.c12e3c345eHigh risk502026-06-10
0.6.5-canary.5243.1.d5ef0cdba5High risk502026-06-10
0.6.5-canary.5242.1.d9d2091843High risk502026-06-10
0.6.5-canary.5241.1.b776822dccHigh risk502026-06-10
0.6.5-canary.5225.2.252ec55eb3High risk252026-06-10
0.6.5-develop.5240.1.bbd9d30275High risk252026-06-10
0.6.5-canary.5229.2.061e491ed3High risk252026-06-10
0.6.5-canary.5239.1.011bfe8cc2High risk252026-06-10
0.6.5-canary.5235.2.176c83e47fHigh risk252026-06-10
0.6.5-canary.5236.2.1b19dce9d6High risk502026-06-10
0.6.5-canary.5233.2.c08c6c4579High risk252026-06-10
0.6.5-canary.5238.1.ca8b2fadc6High risk252026-06-10
0.6.5-canary.5237.1.2904ca4b2dHigh risk502026-06-10
0.6.5-canary.5236.1.1b19dce9d6High risk502026-06-10
0.6.5-canary.5234.1.57b793d127High risk252026-06-10
0.6.5-canary.5235.1.176c83e47fHigh risk252026-06-10
0.6.5-canary.5232.1.b5e070fda2High risk502026-06-10
0.6.5-canary.5233.1.c08c6c4579High risk502026-06-10
0.6.5-canary.5227.1.6b367dc806High risk502026-06-10
0.6.5-develop.5226.1.2cf979f8a3High risk502026-06-10
0.6.5-canary.5231.1.04fc724f8bHigh risk252026-06-10
0.6.5-canary.5230.1.bdde147294High risk502026-06-10
0.6.5-canary.5229.1.061e491ed3High risk252026-06-10
0.6.5-canary.5225.1.252ec55eb3High risk252026-06-10
0.6.5-canary.5222.1.db7c917020High risk252026-06-10
0.6.5-develop.5217.1.e808659271High risk252026-06-10
0.6.5-canary.5220.1.248b0b5d08High risk502026-06-10
0.6.5-canary.5221.1.97e796bf0eHigh risk502026-06-10
0.6.5-canary.5218.1.a833796ec4High risk502026-06-10
0.6.5-canary.5219.1.2a725b421bHigh risk502026-06-10
0.6.5-canary.5216.1.266048b1dcHigh risk502026-06-10
0.6.5-canary.5215.1.b6b53189c0High risk502026-06-10
0.6.5-canary.5203.2.280b910cf7High risk502026-06-10
0.6.5-develop.5212.1.b47932beefHigh risk252026-06-10
0.6.5-canary.5201.2.3bb92d935cHigh risk502026-06-10
0.6.5-canary.5206.1.6d85b55badHigh risk252026-06-10
0.6.5-canary.5192.1.8aed2e3f1dHigh risk502026-06-10
0.6.5-canary.5205.1.f557f4de9aHigh risk502026-06-10
0.6.5-canary.5203.1.280b910cf7High risk502026-06-10
0.6.5-develop.5200.1.871eca3402High risk502026-06-10
0.6.5-canary.5202.1.9ddfe739edHigh risk252026-06-10
0.6.5-canary.5201.1.3bb92d935cHigh risk502026-06-10
0.6.4High risk502026-06-10
0.6.5-canary.5191.1.48fb7f77a4High risk502026-06-10
0.6.5-canary.5190.1.bbeb1e9aeeHigh risk502026-06-10
0.6.5-canary.5188.1.cc8a2d63a9High risk502026-06-10
0.6.5-develop.5187.1.82e5532561High risk252026-06-10
0.6.5-canary.5181.1.a896fb4db6High risk252026-06-10
0.6.5-canary.5179.1.005a6aac7bHigh risk252026-06-10
0.6.5-canary.5178.1.65d4358fb5High risk252026-06-10
0.6.5-canary.5170.1.4c1c96ce62High risk252026-06-10
0.6.5-canary.5173.1.5070fb7465High risk252026-06-10
0.6.5-develop.5169.1.d0671533caHigh risk252026-06-10
0.6.5-canary.5167.1.8bb7f972c7High risk502026-06-10
0.6.5-develop.5166.1.b59e2a71adHigh risk502026-06-10
0.6.5-canary.5163.1.c4c402ce0eHigh risk252026-06-10
0.6.5-develop.5162.1.eba42159b8High risk502026-06-10
0.6.5-canary.5156.1.4f93d8604eHigh risk252026-06-10
0.6.5-canary.5164.1.65d37b2554High risk502026-06-10
0.6.5-canary.5158.1.624b2de81aHigh risk502026-06-10
0.6.5-canary.5138.1.90f733a8e8High risk502026-06-10
0.6.5-develop.5155.1.148d10a46dHigh risk502026-06-10
0.6.5-canary.5157.1.51c9dd436dHigh risk502026-06-10
0.6.5-canary.5146.1.29bd6f35e5High risk502026-06-10
0.6.5-canary.5154.1.87bbb30762High risk502026-06-10
0.6.5-canary.5144.1.201f8f84a2High risk502026-06-10
0.6.5-canary.5142.1.a8def4bd68High risk252026-06-10
0.6.5-develop.5139.1.g7925348493High risk252026-06-10
0.6.5-canary.5135.1.e4ec46692fHigh risk502026-06-10
0.6.5-canary.5132.1.c77f2340edHigh risk502026-06-10
0.6.5-canary.5126.1.59f5a4768fHigh risk252026-06-10
0.6.5-develop.5116.1.f0af9e5080High risk502026-06-10
0.6.5-canary.5118.1.bca444b51fHigh risk252026-06-10
0.6.5-canary.5104.1.85630571c2High risk502026-06-10
0.6.5-develop.5099.1.85c0aff78cHigh risk252026-06-10
0.6.5-canary.5087.1.4f0cfc0942High risk502026-06-10
0.6.5-canary.5049.1.70c6ee70e2High risk502026-06-10
0.6.5-develop.5048.1.fd82f4ae17High risk502026-06-10
0.6.5-canary.5046.1.5d9c38a465High risk502026-06-10
0.6.5-canary.5040.1.ea96298fa5High risk502026-06-10
0.6.5-canary.5039.1.9747b6e7fbHigh risk502026-06-10
0.6.5-canary.5041.1.b10d766b2bHigh risk502026-06-10
0.6.5-canary.5038.1.e9cee0d1b0High risk502026-06-10
0.6.5-develop.5033.1.c970204a3fHigh risk252026-06-10
0.6.5-canary.5037.1.50a27c057aHigh risk502026-06-10
0.6.5-canary.5036.1.2e67f3658fHigh risk252026-06-10
0.6.5-canary.5035.1.55d8c37244High risk252026-06-10
0.6.5-canary.5034.1.97b4fe9417High risk252026-06-10
0.6.5-canary.4994.1.8eba69062bHigh risk252026-06-10
0.6.5-develop.4964.1.ae0edca575High risk252026-06-10
0.6.5-canary.4965.1.96a6701507High risk252026-06-10

Block this in CI

PkgRadar gates @open-mercato/gateway-stripe (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @open-mercato/[email protected]