PkgRadar

npm · registry.npmjs.org

kumidocs

Install-time lifecycle script: postinstall="bun scripts/postinstall.ts"

Why PkgRadar flagged 0.20260531.51

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.20260531.51 vs 0.20260530.50: "bun scripts/postinstall.ts" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.20260531.51High risk452026-06-10
0.20260608.66Review12026-06-08
0.20260607.65Review12026-06-07
0.20260607.64Review12026-06-07
0.20260607.63Review12026-06-07
0.20260607.62Review12026-06-07
0.20260607.61Review12026-06-07
0.20260607.60Review12026-06-07
0.20260607.59Review12026-06-07
0.20260602.58Review12026-06-02
0.20260601.57Review12026-06-01
0.20260601.56Review12026-06-01
0.20260531.55Review12026-05-31
0.20260531.53Review12026-05-31
0.20260531.52Review12026-05-31
0.20260530.50Low risk02026-05-30
0.20260530.49Low risk02026-05-30
0.20260530.48Low risk02026-05-30
0.20260525.47Review62026-05-25
0.20260525.45Review202026-05-25
0.20260525.46Review202026-05-25
0.20260525.42Review202026-05-25
0.20260525.43Review202026-05-25
0.20260524.41Review202026-05-24
0.20260524.40Review202026-05-24
0.20260523.39Review202026-05-24

Block this in CI

PkgRadar gates kumidocs (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]