PkgRadar

npm · registry.npmjs.org

mod-arch-installer

Credential File Packaged: package/flavors/default/frontend/.env

Why PkgRadar flagged 1.20.0

SeveritySignalEvidence
highCredential File Packagedpackage/flavors/default/frontend/.env · package/flavors/default/frontend/.env
highCredential File Packagedpackage/templates/mod-arch-starter/frontend/.env · package/templates/mod-arch-starter/frontend/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
1.20.0Review212026-06-12
1.19.0Review212026-06-10
1.18.0Review212026-06-03
1.16.1Review212026-06-01
1.17.0Review212026-06-01

Block this in CI

PkgRadar gates mod-arch-installer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]