PkgRadar

npm · registry.npmjs.org

create-browserpod-quickstart

Credential File Packaged: package/templates/vite-basic/.env

Why PkgRadar flagged 2.10.0

SeveritySignalEvidence
highCredential File Packagedpackage/templates/vite-basic/.env · package/templates/vite-basic/.env
highCredential File Packagedpackage/templates/vite-web/.env · package/templates/vite-web/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
2.10.0Review212026-06-12
2.6.4Review212026-06-12
2.7.0Review212026-06-12
2.8.0Review212026-06-12
2.9.0Review212026-06-12

Block this in CI

PkgRadar gates create-browserpod-quickstart (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]