PkgRadar

npm · registry.npmjs.org

emailengine-app

Remote Payload: matched "wget "

Why PkgRadar flagged 2.70.0

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · package/copy-static-files.sh
mediumRemote Payloadmatched "curl " · package/getswagger.sh
mediumRemote Payloadmatched "github.com/postalsys/emailengine/releases/download" · package/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2.70.0Review122026-06-15
2.71.0Review122026-06-15
2.69.0Review122026-06-09
2.68.1Review122026-06-01
2.67.3Review312026-05-26
2.68.0Review312026-05-26

Block this in CI

PkgRadar gates emailengine-app (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]