PkgRadar

npm · registry.npmjs.org

codex-plugin-doctor

Remote Payload: matched "invoke-webrequest"

Why PkgRadar flagged 1.3.0

SeveritySignalEvidence
mediumRemote Payloadmatched "invoke-webrequest" · package/dist/security/security-audit.js
mediumRemote Payloadmatched "invoke-webrequest" · package/dist/security/trust-score.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.19.0Low risk02026-06-13
1.18.0Low risk02026-06-12
1.16.0Low risk02026-06-10
1.17.0Low risk02026-06-10
1.15.0Low risk02026-06-08
1.14.0Low risk02026-06-07
1.13.0Low risk02026-06-06
1.12.1Low risk02026-06-05
1.11.0Low risk02026-06-04
1.10.0Low risk02026-06-03
1.9.0Low risk02026-06-01
1.8.0Low risk02026-05-31
1.7.0Low risk02026-05-28
1.6.0Low risk02026-05-27
1.5.0Low risk02026-05-26
1.3.0Review242026-05-24
1.4.0Review242026-05-24

Block this in CI

PkgRadar gates codex-plugin-doctor (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]