PkgRadar

npm · registry.npmjs.org

betanxt-design-tokens

Install-time lifecycle script: postinstall="npm run docs:install"

Why PkgRadar flagged 1.0.98

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 1.0.98 vs 1.0.92: "npm run docs:install" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.98High risk452026-06-10
1.1.0Review22026-06-10
1.0.99Review22026-06-09
1.0.9Low risk02026-06-09
1.0.91Low risk02026-06-09
1.0.92Low risk02026-06-09

Block this in CI

PkgRadar gates betanxt-design-tokens (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]