PkgRadar

npm · registry.npmjs.org

@planu/cli

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 4.7.1

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/engine/llm-runtime/pricing-resolver.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.7.1Review302026-06-13
4.7.0Review302026-06-13
4.6.1Review302026-06-12
4.6.0Review212026-06-11
4.5.0Review212026-06-10
4.4.3Review212026-06-10
4.4.2Review212026-06-05
4.4.1Review212026-06-04
4.4.0Review302026-06-03
4.3.25Review212026-06-03
4.3.23Review212026-06-02
4.3.24Review212026-06-02
4.3.22Review212026-06-02
4.3.21Review212026-06-02
4.3.19Review212026-05-30
4.3.20Review212026-05-30
4.3.15Review302026-05-30
4.3.14Review212026-05-30
4.3.12Review212026-05-30
4.3.13Review302026-05-30
4.3.10Review1652026-05-25
4.3.9Review1652026-05-25
4.3.5Review1602026-05-25
4.3.4Review1602026-05-25
4.3.8Review1652026-05-25
4.3.7Review1652026-05-25
4.3.6Review1652026-05-25

Block this in CI

PkgRadar gates @planu/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @planu/[email protected]