PkgRadar

npm · registry.npmjs.org

create-exam-cli

Credential File Packaged: package/templates/mysql/backend/.env

Why PkgRadar flagged 1.0.27

SeveritySignalEvidence
highCredential File Packagedpackage/templates/mysql/backend/.env · package/templates/mysql/backend/.env
highCredential File Packagedpackage/templates/sql/backend/.env · package/templates/sql/backend/.env
highCredential File Packagedpackage/templates/stock/backend/.env · package/templates/stock/backend/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.27High risk1002026-06-03
1.0.29High risk1002026-06-03
1.0.26High risk1002026-06-03
1.0.19High risk702026-06-03
1.0.20High risk702026-06-03
1.0.15High risk242026-06-03
1.0.25High risk1002026-06-03
1.0.23High risk702026-06-03
1.0.24High risk702026-06-03
1.0.22High risk1002026-06-03
1.0.21High risk1002026-06-03
1.0.13Review592026-05-25
1.0.14Review592026-05-25

Block this in CI

PkgRadar gates create-exam-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]