PkgRadar

npm · registry.npmjs.org

webpb

Remote Payload: matched "github.com/jinganix/webpb/releases/download"

Why PkgRadar flagged 0.0.28

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/jinganix/webpb/releases/download" · package/cli/resolve-protoc-plugin.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.28Review32026-06-12
0.0.27Review32026-06-12
0.0.23Low risk02026-06-12
0.0.24Low risk02026-06-12
0.0.25Low risk02026-06-12
0.0.26Low risk02026-06-12

Block this in CI

PkgRadar gates webpb (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]