PkgRadar

npm · registry.npmjs.org

taon

Remote Payload: matched "curl "

Why PkgRadar flagged 21.0.104

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/lib-esm/lib/endpoint-context.js
mediumRemote Payloadmatched "curl " · package/lib-prod/endpoint-context.js
mediumRemote Payloadmatched "curl " · package/lib/endpoint-context.js
mediumRemote Payloadmatched "curl " · package/websql-prod/fesm2022/taon-websql-prod.mjs
mediumRemote Payloadmatched "curl " · package/websql/fesm2022/taon-websql.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
21.0.120Low risk02026-06-05
21.0.122Low risk02026-06-05
21.0.104Review502026-05-24
21.0.105Review502026-05-24

Related campaigns

Block this in CI

PkgRadar gates taon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]