PkgRadar

npm · registry.npmjs.org

@trenchwork/vigil

New Account With Lifecycle Hook: package first published 16 day(s) ago, 5 total version(s), has lifecycle hook

Why PkgRadar flagged 2.0.4

SeveritySignalEvidence
highNew Account With Lifecycle Hookpackage first published 16 day(s) ago, 5 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.17Review152026-06-16
2.0.18Review152026-06-16
2.0.16Review152026-06-16
2.0.14Review152026-06-16
2.0.15Review152026-06-16
2.0.13Review152026-06-16
2.0.12Review152026-06-16
2.0.11Review152026-06-16
2.0.10Review152026-06-16
2.0.9Review152026-06-15
2.0.8Review152026-06-15
2.0.7Review152026-06-15
2.0.6Review152026-06-15
2.0.5Review152026-06-15
2.0.4High risk152026-06-15
2.0.3High risk152026-06-15
2.0.2High risk152026-06-15
1.1.38High risk82026-06-15
2.0.1High risk152026-06-15

Block this in CI

PkgRadar gates @trenchwork/vigil (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @trenchwork/[email protected]