PkgRadar

npm · registry.npmjs.org

powered-immersive-header

Install Lifecycle Remote Or Exec: preinstall="node -e \"if(!process.env.npm_execpath || !process.env.npm_execpath.includes('yarn')) { console.error('\\x1b[31mError: Use yarn to install dependencies.\\x1b[0m'); process.exit(1); }\""

Why PkgRadar flagged 0.0.79

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspreinstall added in 0.0.79 vs 0.0.76: "node -e \"if(!process.env.npm_execpath || !process.env.npm_execpath.includes('yarn')) { console.error('\\x1b[31mError: Use yarn to install dependencies.\\x1b[0m'); process.exit(1); }\"" · package.json
highInstall Lifecycle Remote Or Execpreinstall="node -e \"if(!process.env.npm_execpath || !process.env.npm_execpath.includes('yarn')) { console.error('\\x1b[31mError: Use yarn to install dependencies.\\x1b[0m'); process.exit(1); }\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.75Low risk02026-06-09
0.0.76Low risk02026-06-09
0.0.79High risk752026-06-09
0.0.80Low risk02026-06-09

Block this in CI

PkgRadar gates powered-immersive-header (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]