PkgRadar

npm · registry.npmjs.org

nexvora

Install-time lifecycle script: postinstall="node scripts/postinstall.mjs"

Why PkgRadar flagged 0.2.1

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.2.1 vs 0.2.0: "node scripts/postinstall.mjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.16Review32026-06-11
0.4.15Review32026-06-10
0.4.14Review32026-06-10
0.4.13Review32026-06-10
0.4.12Review32026-06-10
0.4.11Review32026-06-10
0.2.1High risk452026-06-10
0.4.10Review32026-06-10
0.4.9Review32026-06-10
0.4.8Review32026-06-09
0.4.7Review32026-06-09
0.4.6Review32026-06-09
0.4.4Review32026-06-09
0.4.5Review32026-06-09
0.4.3Review32026-06-09
0.4.2Review32026-06-09
0.4.1Review32026-06-09
0.4.0Review32026-06-09
0.3.20Review32026-06-08
0.3.19Review52026-06-08
0.3.18Review32026-06-08
0.3.17Review32026-06-08
0.3.16Review52026-06-08
0.3.15Review52026-06-08
0.3.14Review32026-06-08
0.3.13Review52026-06-08
0.3.11Review52026-06-08
0.3.10Review52026-06-08
0.3.9Review52026-06-08
0.3.8Review32026-06-08
0.3.7Review32026-06-08
0.3.6Review32026-06-08
0.3.5Review52026-06-08
0.3.4Review52026-06-08
0.3.3Review32026-06-08
0.3.2Review32026-06-07
0.2.3Review52026-06-05
0.2.2Review52026-06-02
0.2.0Low risk02026-06-02
0.1.6Low risk02026-06-01
0.1.5Low risk02026-06-01
0.1.4Low risk02026-06-01
0.1.3Low risk02026-06-01
0.1.0Low risk02026-06-01

Block this in CI

PkgRadar gates nexvora (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]