PkgRadar

npm · registry.npmjs.org

plannar

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.0.4

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/dist/ssh-config-DAsGgEig.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/blade-CKDp56sR.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/julia-B3gTKp-V.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/php-DcghqDXq.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.0Low risk02026-06-10
1.0.0Low risk02026-05-28
0.0.5Low risk02026-05-25
0.0.4Review302026-05-25
0.0.3Review302026-05-25
0.0.2Review302026-05-25
0.0.1Review302026-05-24

Related campaigns

Block this in CI

PkgRadar gates plannar (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]