PkgRadar

npm · registry.npmjs.org

@wabot-dev/framework

Remote Payload: matched "cUrl "

Why PkgRadar flagged 0.9.22

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/dist/src/addon/chat-bot/anthropic/AnthropicChatAdapter.js
mediumRemote Payloadmatched "cUrl " · package/dist/src/addon/chat-bot/openia/OpenaiChatAdapter.js
mediumRemote Payloadmatched "cUrl " · package/dist/src/addon/chat-bot/openrouter/OpenRouterChatAdapter.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.14Low risk02026-06-10
0.9.80Low risk02026-06-10
0.9.27Low risk02026-06-06
0.9.26Low risk02026-06-06
0.9.25Low risk02026-06-06
0.9.24Low risk02026-06-05
0.9.23Low risk02026-06-05
0.9.22Review362026-05-25
0.9.20Review362026-05-24
0.9.21Review362026-05-24

Block this in CI

PkgRadar gates @wabot-dev/framework (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @wabot-dev/[email protected]