PkgRadar

npm · registry.npmjs.org

codeceptjs

Remote Payload: matched "cURL "

Why PkgRadar flagged 4.0.2

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · package/lib/helper/REST.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.0-rc.0Low risk02026-06-13
4.0.6Low risk02026-06-09
4.0.5Low risk02026-06-08
4.0.4Low risk02026-06-05
4.0.3Low risk02026-05-28
4.0.2Review122026-05-24
4.0.1Review122026-05-24

Block this in CI

PkgRadar gates codeceptjs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]