PkgRadar

npm · registry.npmjs.org

cursorconnect

Install-time lifecycle script: postinstall="node dist/postinstall.js"

Why PkgRadar flagged 0.1.2

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.1.2 vs 0.1.0: "node dist/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.2High risk452026-06-03
1.0.2Review32026-06-03
1.0.1Review52026-06-02
1.0.0Review52026-06-01
0.1.26Review32026-06-01
0.1.25Review52026-06-01
0.1.24Review32026-06-01
0.1.22Review32026-05-30
0.1.21Review52026-05-30
0.1.20Review32026-05-30
0.1.19Review32026-05-30
0.1.18Review52026-05-30
0.1.16Review52026-05-30
0.1.17Review32026-05-30
0.1.14Review52026-05-30
0.1.13Review32026-05-30
0.1.8Review32026-05-30
0.1.7Review32026-05-30
0.1.6Review32026-05-30
0.1.5Review52026-05-30
0.1.4Review32026-05-30
0.1.23Review52026-05-29

Related campaigns

Block this in CI

PkgRadar gates cursorconnect (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]