npm · registry.npmjs.org
create-zuplo-api
Credential file access: matched ".npmrc"
Why PkgRadar flagged 6.70.48
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | matched ".npmrc" · package/dist/index.js |
| medium | Remote Payload | matched "raw.githubusercontent.com" · package/dist/index.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
6.71.2 | Low risk | 0 | 2026-06-16 |
6.71.1 | Low risk | 0 | 2026-06-16 |
6.71.0 | Low risk | 0 | 2026-06-15 |
6.70.71 | Low risk | 0 | 2026-06-12 |
6.70.70 | Low risk | 0 | 2026-06-10 |
6.70.69 | Low risk | 0 | 2026-06-09 |
6.70.68 | Low risk | 0 | 2026-06-09 |
6.70.67 | Low risk | 0 | 2026-06-08 |
6.70.66 | Low risk | 0 | 2026-06-06 |
6.70.63 | Low risk | 0 | 2026-06-04 |
6.70.62 | Low risk | 0 | 2026-06-03 |
6.70.61 | Low risk | 0 | 2026-06-02 |
6.70.60 | Low risk | 0 | 2026-06-02 |
6.70.59 | Low risk | 0 | 2026-06-01 |
6.70.57 | Low risk | 0 | 2026-05-29 |
6.70.56 | Low risk | 0 | 2026-05-28 |
6.70.55 | Low risk | 0 | 2026-05-28 |
6.70.54 | Low risk | 0 | 2026-05-28 |
6.70.53 | Low risk | 0 | 2026-05-27 |
6.70.51 | Low risk | 0 | 2026-05-27 |
6.70.50 | Low risk | 0 | 2026-05-26 |
6.70.49 | Low risk | 0 | 2026-05-25 |
6.70.48 | Review | 42 | 2026-05-24 |
6.70.47 | Review | 42 | 2026-05-24 |
6.70.46 | Review | 42 | 2026-05-24 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]