PkgRadar

npm · registry.npmjs.org

@unerr-ai/unerr

Install Lifecycle Suppresses Failure: postinstall="node scripts/postinstall.mjs || true"

Why PkgRadar flagged 0.2.7

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="node scripts/postinstall.mjs || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.7High risk252026-06-13
0.2.6High risk252026-06-13
0.2.12Low risk02026-06-12
0.2.12-canary.0Low risk02026-06-12
0.2.5High risk172026-06-10
0.2.3High risk172026-06-10
0.2.4High risk172026-06-10
0.2.2High risk252026-06-10
0.2.0High risk252026-06-10
0.2.1High risk252026-06-10
0.1.8High risk252026-06-10
0.1.9High risk172026-06-10
0.2.8High risk172026-06-10
0.2.11Low risk02026-06-02
0.2.10Low risk02026-06-01
0.2.9Low risk02026-06-01
1.0.0-beta.1High risk402026-05-25

Block this in CI

PkgRadar gates @unerr-ai/unerr (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @unerr-ai/[email protected]