PkgRadar

npm · registry.npmjs.org

foliko

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.1.8

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/plugins/plugin-manager-plugin.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/cli/src/commands/plugin.js
mediumRemote Payloadmatched "curl " · package/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.8Review252026-06-10
1.1.6Review252026-06-10
1.1.5Review272026-06-10
1.1.83Review252026-06-10
1.1.82Review252026-06-09
1.1.81Review252026-06-09
1.1.80Review362026-06-09
1.1.79Review362026-06-09
1.1.78Review362026-06-09
1.1.77Review362026-06-08
1.1.76Review362026-06-02
1.1.75Review362026-05-30
1.1.73Review252026-05-29
1.1.72Review362026-05-29
1.1.71Review252026-05-29
1.1.69Review252026-05-29
1.1.70Review252026-05-29
1.1.68Review352026-05-25
1.1.66Review252026-05-25
1.1.67Review352026-05-25

Block this in CI

PkgRadar gates foliko (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]