PkgRadar

npm · registry.npmjs.org

homebridge-config-ui-x

Remote Payload: matched "github.com/homebridge/plugin-repo/releases/download"

Why PkgRadar flagged 4.54.2-beta.16

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/homebridge/plugin-repo/releases/download" · package/plugin-upgrade-install.sh
mediumRemote Payloadmatched "curl " · package/upgrade-install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
4.54.2-beta.16Review102026-06-10
4.54.2-beta.17Review102026-06-10
4.54.2-beta.18Review102026-06-10
5.24.1-beta.4Review82026-06-10
5.24.1-beta.3Review82026-06-05
5.24.1-beta.2Review82026-06-04
5.24.1-beta.1Review82026-06-03
6.0.0-alpha.1Review82026-06-01
6.0.0-alpha.0Review82026-06-01
5.24.1-beta.0Review82026-05-31
5.24.0Review82026-05-31
5.23.1-beta.28Review82026-05-31
5.23.1-beta.27Review82026-05-31
5.23.1-beta.26Review82026-05-30
5.23.1-beta.25Review82026-05-30
5.23.1-beta.24Review82026-05-30
5.23.1-beta.23Review82026-05-29
5.23.1-beta.22Review102026-05-28
5.23.1-beta.21Review242026-05-28
5.23.1-beta.19Review242026-05-28
5.23.1-beta.20Review242026-05-28
5.23.1-beta.17Review312026-05-28
5.23.1-beta.18Review312026-05-28
5.23.1-beta.15Review312026-05-27
5.23.1-beta.13Review312026-05-27
5.23.1-beta.14Review312026-05-27
5.23.1-beta.7Review1242026-05-24
5.23.1-beta.8Review1242026-05-24

Block this in CI

PkgRadar gates homebridge-config-ui-x (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]