PkgRadar

npm · registry.npmjs.org

syllable-sdk

Large Javascript Payload: 3367001 bytes

Why PkgRadar flagged 1.0.44-rc.5

SeveritySignalEvidence
mediumLarge Javascript Payload3367001 bytes · package/bin/mcp-server.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.48-rc.5Low risk02026-06-13
1.0.48-rc.4Low risk02026-06-12
1.0.48-rc.3Low risk02026-06-11
1.0.48-rc.2Low risk02026-06-10
1.0.48-rc.1Low risk02026-06-10
1.0.47Low risk02026-06-09
1.0.47-rc.8Low risk02026-06-09
1.0.47-rc.7Low risk02026-06-09
1.0.47-rc.6Low risk02026-06-08
1.0.47-rc.5Low risk02026-06-06
1.0.47-rc.4Low risk02026-06-05
1.0.47-rc.3Low risk02026-06-05
1.0.47-rc.2Low risk02026-06-05
1.0.46Low risk02026-06-04
1.0.47-rc.1Low risk02026-06-04
1.0.46-rc.3Low risk02026-06-04
1.0.46-rc.2Low risk02026-06-03
1.0.46-rc.1Low risk02026-06-03
1.0.45Low risk02026-06-02
1.0.45-rc.3Low risk02026-06-01
1.0.45-rc.2Low risk02026-05-30
1.0.44Low risk02026-05-29
1.0.45-rc.1Low risk02026-05-29
1.0.44-rc.5Review32026-05-28
1.0.44-rc.4Review32026-05-27
1.0.44-rc.2Review32026-05-26
1.0.44-rc.3Review32026-05-26

Block this in CI

PkgRadar gates syllable-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]