PkgRadar

npm · registry.npmjs.org

rudder-sdk-js

Install-time lifecycle script: postinstall="echo 'This package is deprecated and no longer maintained. While your events are still being tracked and delivered, we strongly recommend you to migrate to the latest @rudderstack/analytics-js (https://www.npmjs.com/package/@rudderstack/analytics-js) package for enhanced features, security updates, and ongoing support. For more details, visit the migration guide: https://www.rudderstack.com/docs/sources/event-streams/sdks/rudderstack-javascript-sdk/migration-guide/'"

Why PkgRadar flagged 2.52.8-beta.pr.2745.191e32d

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2.52.8-beta.pr.2745.191e32d vs 2.52.8-beta.pr.2744.f99ccd7: "echo 'This package is deprecated and no longer maintained. While your events are still being tracked and delivered, we strongly recommend you to migrate to the latest @rudderstack/analytics-js (https://www.npmjs.com/package/@rudderstack/analytics-js) package for enhanced features, security updates, and ongoing support. For more details, visit the migration guide: https://www.rudderstack.com/docs/sources/event-streams/sdks/rudderstack-javascript-sdk/migration-guide/'" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.52.13Review12026-06-08
2.52.11Review12026-06-08
2.52.12Review12026-06-08
2.52.8-beta.pr.2745.191e32dHigh risk452026-06-08
2.52.9Review12026-06-08

Block this in CI

PkgRadar gates rudder-sdk-js (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]