PkgRadar

npm · registry.npmjs.org

@zhiman_innies/innies-codex

Install-time lifecycle script: postinstall="node bin/innies-init.js"

Why PkgRadar flagged 0.122.40

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.122.40 vs 0.122.39: "node bin/innies-init.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.122.50Review12026-06-13
0.122.51Review12026-06-13
0.122.49Review12026-06-12
0.122.48Review12026-06-12
0.122.47Review12026-06-12
0.122.40High risk452026-06-10
0.122.46Review12026-06-08
0.122.45Review12026-06-07
0.122.44Review52026-06-07
0.122.43Review52026-06-07
0.122.42Review52026-06-06
0.122.41Review52026-06-06
0.122.39Low risk02026-06-06
0.122.37Review52026-06-04
0.122.36Review52026-06-03
0.122.33Review102026-05-27
0.122.35Review102026-05-27

Block this in CI

PkgRadar gates @zhiman_innies/innies-codex (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @zhiman_innies/[email protected]