PkgRadar

npm · registry.npmjs.org

@thinhnguyencth1204/nextcli

Credential File Packaged: package/templates/next-base/.env

Why PkgRadar flagged 0.4.2

SeveritySignalEvidence
highCredential File Packagedpackage/templates/next-base/.env · package/templates/next-base/.env
mediumNew Account With Lifecycle Hookpackage first published 10 day(s) ago, 7 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.2High risk402026-06-11
0.4.1High risk402026-06-11
0.4.0High risk402026-06-11
0.3.0High risk802026-06-11
0.2.1High risk352026-06-11
0.2.0High risk352026-06-10
0.1.0High risk352026-06-10

Related campaigns

Block this in CI

PkgRadar gates @thinhnguyencth1204/nextcli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @thinhnguyencth1204/[email protected]