PkgRadar

npm · registry.npmjs.org

@techninja/staticart

Credential File Packaged: package/templates/.env

Why PkgRadar flagged 0.4.15

SeveritySignalEvidence
highCredential File Packagedpackage/templates/.env · package/templates/.env
highInstall Lifecycle Remote Or Execpostinstall="node scripts/setup.js" · package.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/api/package-lock.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.15Review242026-05-25
0.4.16Review242026-05-25

Block this in CI

PkgRadar gates @techninja/staticart (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @techninja/[email protected]