PkgRadar

npm · registry.npmjs.org

@saputzx/baileys

Remote Dependency Spec: dependencies.libsignal="github:adiwajshing/libsignal-node"

Why PkgRadar flagged 1.0.0-beta

SeveritySignalEvidence
mediumRemote Dependency Specdependencies.libsignal="github:adiwajshing/libsignal-node" · package.json
mediumNew Account With Lifecycle Hookpackage first published 52 day(s) ago, 6 total version(s), has lifecycle hook · package.json
mediumRemote Dependency SpecdevDependencies.@adiwajshing/eslint-config="github:adiwajshing/eslint-config" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-betaHigh risk252026-06-20
3.0.0Review132026-06-17
4.0.0Review132026-06-17
5.0.0Review132026-06-17

Block this in CI

PkgRadar gates @saputzx/baileys (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @saputzx/[email protected]
@saputzx/baileys — npm security scan | PkgRadar