PkgRadar

npm · registry.npmjs.org

crawlforge-mcp-server

Known Indicator Filename: package/src/cli/commands/stealth.js

Why PkgRadar flagged 4.6.6

SeveritySignalEvidence
highKnown Indicator Filenamepackage/src/cli/commands/stealth.js · package/src/cli/commands/stealth.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.6.6High risk352026-06-16
4.6.5High risk352026-06-16
4.2.11High risk352026-06-10
4.2.10High risk352026-06-10
4.2.8High risk352026-06-10
4.6.4High risk352026-06-10
4.6.3High risk352026-06-10
4.6.2High risk352026-06-10
4.6.1High risk352026-06-10
4.6.0High risk352026-06-10
4.5.0High risk352026-06-10
4.2.12High risk352026-06-10
4.2.5High risk352026-06-10
4.2.6High risk352026-06-10
4.2.2High risk352026-06-10
4.2.3High risk352026-06-10

Block this in CI

PkgRadar gates crawlforge-mcp-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]