PkgRadar

npm · registry.npmjs.org

@qctrl/visualizer

Credential File Packaged: package/.env

Why PkgRadar flagged 3.1.4

SeveritySignalEvidence
highCredential File Packagedpackage/.env · package/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
3.1.4Review102026-06-14
4.0.3Low risk02026-06-14
4.1.1Low risk02026-06-14
6.2.4Review12026-06-14
7.0.0Review12026-06-14
8.0.0Review12026-06-14
8.0.1Review12026-06-14

Block this in CI

PkgRadar gates @qctrl/visualizer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @qctrl/[email protected]