PkgRadar

npm · registry.npmjs.org

kentutai

Credential File Packaged: package/app/.env

Why PkgRadar flagged 1.3.0

SeveritySignalEvidence
highCredential File Packagedpackage/app/.env · package/app/.env
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/app/node_modules/next/dist/lib/mkcert.js
mediumRemote Payloadmatched "Curl " · package/app/cli/app/src/app/(dashboard)/dashboard/media-providers/[kind]/[id]/page.js
mediumRemote Payloadmatched "Curl " · package/app/src/app/(dashboard)/dashboard/media-providers/[kind]/[id]/page.js
mediumRemote Payloadmatched "curl " · package/app/.next/node_modules/better-sqlite3-90e2652d1716b047/deps/download.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.0High risk982026-06-13
1.1.0High risk562026-06-10
1.0.0High risk682026-06-10
1.0.1High risk682026-06-10
1.7.0High risk622026-06-10
1.7.15Review222026-06-05
1.7.11Review152026-06-05
1.7.5Review222026-06-03
1.7.6Review152026-06-03
1.7.4Review222026-05-31
1.7.3Review222026-05-31
1.7.2Review222026-05-31
1.7.1Review222026-05-31
1.5.0Low risk02026-05-31

Block this in CI

PkgRadar gates kentutai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]