PkgRadar

npm · registry.npmjs.org

@tmecontinue/claude

Install-time lifecycle script: postinstall="node scripts/run-cleanup-update-pending.cjs"

Why PkgRadar flagged 2.2.15-beta.3

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2.2.15-beta.3 vs 2.2.15-beta.2: "node scripts/run-cleanup-update-pending.cjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.1-securityLow risk02026-06-01
2.2.15-beta.25Review32026-06-01
2.2.15-beta.24Review32026-06-01
2.2.15-beta.23Review32026-06-01
2.2.15-beta.22Review32026-06-01
2.2.15-beta.21Review32026-06-01
2.2.15-beta.20Review32026-06-01
2.2.15-beta.19Review32026-06-01
2.2.15-beta.3High risk452026-05-30
2.2.15-beta.17Review52026-05-29
2.2.15-beta.18Review52026-05-29
2.2.15-beta.5Review102026-05-29
2.2.15-beta.6Review102026-05-29
2.1.150-beta.1Review52026-05-29
2.2.15-beta.1Review1722026-05-25
2.2.15-beta.2Review1722026-05-25

Block this in CI

PkgRadar gates @tmecontinue/claude (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tmecontinue/[email protected]