PkgRadar

npm · registry.npmjs.org

framepack

Install-time lifecycle script: postinstall="node scripts/postinstall.mjs"

Why PkgRadar flagged 0.5.0-alpha.2

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.5.0-alpha.2 vs 0.5.0-alpha.1: "node scripts/postinstall.mjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.0-alpha.2High risk452026-06-10
0.6.0-alpha.4Review32026-06-06
0.6.0-alpha.3Review32026-06-05
0.6.0-alpha.2Review32026-05-30
0.6.0-alpha.1Review52026-05-30
0.5.0-beta.1Review32026-05-30
0.5.0-alpha.26Review52026-05-30
0.5.0-alpha.16Review52026-05-30
0.5.0-alpha.15Review52026-05-30
0.5.0-alpha.14Review32026-05-30
0.5.0-alpha.13Review52026-05-30
0.5.0-alpha.12Review52026-05-30
0.5.0-alpha.11Review52026-05-30
0.5.0-alpha.7Review52026-05-30
0.5.0-alpha.8Review52026-05-30
0.5.0-alpha.6Review52026-05-30
0.5.0-alpha.5Review32026-05-30
0.5.0-alpha.25Review52026-05-30
0.5.0-alpha.3Review52026-05-30
0.5.0-alpha.1Low risk02026-05-30
0.5.0-alpha.24Review52026-05-30
0.4.0-beta.2Low risk02026-05-30
0.5.0-alpha.23Review32026-05-30
0.5.0-alpha.22Review52026-05-30
0.5.0-alpha.20Review32026-05-29
0.5.0-alpha.19Review32026-05-29
0.5.0-alpha.18Review32026-05-29
0.4.0-alpha.4Review572026-05-24
0.4.0-beta.1Review572026-05-24

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates framepack (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]