PkgRadar

npm · registry.npmjs.org

dotenv-express

Suspicious Publish Context: {"package_age_days":0,"publisher":"jeandupont24","burst_same_day":2,"burst_week":2,"lure":{"kind":"token_affix","target":"dotenv"},"version_anomaly":true,"new_account":true}

Why PkgRadar flagged 17.4.5

SeveritySignalEvidence
mediumSuspicious Publish Context{"package_age_days":0,"publisher":"jeandupont24","burst_same_day":2,"burst_week":2,"lure":{"kind":"token_affix","target":"dotenv"},"version_anomaly":true,"new_account":true}

Scanned versions

VersionVerdictScoreScanned (UTC)
17.4.5Review102026-06-13
17.4.6Review102026-06-13
17.4.4Review102026-06-13
17.4.3Review102026-06-13
17.4.2Review102026-06-13

Block this in CI

PkgRadar gates dotenv-express (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]