PkgRadar

npm · registry.npmjs.org

vibecoding-installer

Manifest Codeless Dependency Stub: package ships no JS/TS source but declares 8 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape

Why PkgRadar flagged 0.1.42

SeveritySignalEvidence
mediumManifest Codeless Dependency Stubpackage ships no JS/TS source but declares 8 dependency(ies) (0 with loose/empty version specs) — dependency-confusion / install-chain loader shape · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.42Review102026-06-16
0.1.41Review102026-06-16
0.1.40Review102026-06-15
0.1.38Review152026-06-13
0.1.37Review152026-06-13
0.1.36Review152026-06-12
0.1.34-2-gc5d2acaReview102026-06-11
0.1.34Review152026-06-08
0.1.32-1-ge809272Review102026-06-08
0.1.30-dirtyReview152026-06-02
0.1.31Review102026-06-02
0.1.29-dirtyReview152026-06-01
0.1.28-3-g40ac2e8Review152026-06-01
0.1.28-2-gb2f78d3-dirtyReview102026-06-01
0.1.27-dirtyReview102026-05-31
0.1.26-14-gf0f6f9c-dirtyReview32026-05-30
0.1.26-5-g221dccd-dirtyReview52026-05-30
0.1.25-11-g0da8752-dirtyReview52026-05-30
0.1.25-1-g263c076-dirtyReview52026-05-30
0.1.24-2-g4a0b022-dirtyReview32026-05-30
0.1.22-dirtyReview52026-05-30
0.1.23-dirtyReview52026-05-30
0.1.21-1-g85666b3-dirtyReview52026-05-30
0.1.20-2-ga9e236c-dirtyReview52026-05-30
0.1.20-dirtyReview52026-05-30
0.1.19-dirtyReview52026-05-30
0.1.18-dirtyReview52026-05-30

Block this in CI

PkgRadar gates vibecoding-installer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]