PkgRadar

npm · registry.npmjs.org

@vercel/geistdocs

Install-time lifecycle script: postinstall="fumadocs-mdx"

Why PkgRadar flagged 1.2.3-canary.1d733b2

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 1.2.3-canary.1d733b2 vs 1.2.2: "fumadocs-mdx" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.3-canary.1d733b2High risk452026-06-10
1.7.2Review12026-06-09
1.7.1Review12026-06-05
1.7.0Review12026-06-04
1.6.0Review12026-06-04
1.6.1Review12026-06-04
1.5.0Review12026-06-03
1.4.1Review12026-06-02
1.4.0Review12026-06-02
1.3.1Review12026-06-01
1.2.3-canary.73598cfReview12026-05-29
1.3.0Review12026-05-29
1.2.3-canary.53ff3dbReview12026-05-29
1.2.3-canary.a12a9c6Review12026-05-25
1.2.3-canary.fd2c9a6Review12026-05-25

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @vercel/geistdocs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vercel/[email protected]