PkgRadar

npm · registry.npmjs.org

nolimit-x

Install-time lifecycle script: postinstall="node scripts/postinstall.js"

Why PkgRadar flagged 1.0.223

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 1.0.223 vs 1.0.222: "node scripts/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.277Review32026-06-10
1.0.275Review32026-06-10
1.0.274Review32026-06-10
1.0.223High risk452026-06-10
1.0.273Review32026-06-10
1.0.272Review32026-06-10
1.0.271Review32026-06-09
1.0.270Review32026-06-09
1.0.269Review32026-06-09
1.0.268Review32026-06-09
1.0.267Review32026-06-09
1.0.266Review32026-06-09
1.0.265Review32026-06-09
1.0.264Review32026-06-09
1.0.263Review32026-06-09
1.0.262Review32026-06-09
1.0.261Review32026-06-08
1.0.260Review32026-06-08
1.0.259Review32026-06-08
1.0.258Review32026-06-08
1.0.257Review32026-06-08
1.0.256Review32026-06-08
1.0.255Review32026-06-08
1.0.254Review32026-06-07
1.0.252Review32026-06-07
1.0.251Review32026-06-07
1.0.250Review32026-06-07
1.0.249Review32026-06-07
1.0.247Review32026-06-07
1.0.246Review32026-06-07
1.0.245Review32026-06-06
1.0.244Review32026-06-06
1.0.243Review32026-06-06
1.0.242Review32026-06-06
1.0.241Review32026-06-04
1.0.240Review32026-06-04
1.0.239Review32026-06-04
1.0.238Review32026-06-04
1.0.237Review32026-06-04
1.0.236Review32026-06-04
1.0.235Review32026-06-04
1.0.234Review32026-06-04
1.0.233Review32026-06-04
1.0.232Review32026-06-04
1.0.231Review32026-06-04
1.0.230Review32026-06-04
1.0.229Review32026-06-04
1.0.226Review32026-05-30
1.0.227Review32026-05-30
1.0.225Review32026-05-30
1.0.228Review32026-05-29
1.0.215Review162026-05-27
1.0.216Review82026-05-27
1.0.212Review82026-05-25
1.0.211Low risk02026-05-25
1.0.210Review302026-05-24
1.0.209Review302026-05-24

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates nolimit-x (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]