PkgRadar

npm · registry.npmjs.org

@open-wa/core

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 5.0.0-alpha.7

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/transport/assets/wapi.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/transport/assets/wapi.js

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.0-alpha.7Review242026-06-17
5.0.0-alpha.6Review242026-06-17
5.0.0-alpha.5Review242026-06-17
5.0.0-alpha.4Review242026-06-17
5.0.0-alpha.3Review242026-06-17
5.0.0-alpha.2Review242026-06-17
5.0.0-alpha.0Review242026-06-17

Block this in CI

PkgRadar gates @open-wa/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @open-wa/[email protected]
@open-wa/core — npm security scan | PkgRadar