PkgRadar

npm · registry.npmjs.org

create-berna-stencil

Credential File Packaged: package/src/api/core/vendor/vlucas/phpdotenv/tests/fixtures/env/.env

Why PkgRadar flagged 1.0.25

SeveritySignalEvidence
highCredential File Packagedpackage/src/api/core/vendor/vlucas/phpdotenv/tests/fixtures/env/.env · package/src/api/core/vendor/vlucas/phpdotenv/tests/fixtures/env/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.25High risk402026-06-10
2.4.3High risk402026-06-10
2.0.0High risk402026-06-10
2.0.1High risk402026-06-10
2.4.1High risk402026-06-10
2.4.0High risk402026-06-10
2.3.0High risk402026-06-10
2.2.1High risk402026-06-10
2.2.0High risk402026-06-10
2.1.0High risk402026-06-10
2.0.13High risk402026-06-10
2.0.12High risk402026-06-10
2.0.8High risk402026-06-10
2.0.7High risk402026-06-10
2.0.6High risk402026-06-10
2.0.5High risk402026-06-10
2.0.3High risk402026-06-10
2.0.4High risk402026-06-10
2.4.2Review52026-06-09
2.0.15Review52026-06-04
2.0.14Review52026-06-04
2.0.9Review52026-06-03
2.0.2Review52026-05-28

Block this in CI

PkgRadar gates create-berna-stencil (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]