PkgRadar

npm · registry.npmjs.org

wotann

Install Lifecycle Remote Or Exec: postinstall="node -e \"try { require('node:fs').chmodSync('dist/index.js', 0o755); } catch {}\""

Why PkgRadar flagged 0.5.98

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try { require('node:fs').chmodSync('dist/index.js', 0o755); } catch {}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.98Review222026-06-01
0.5.97Review222026-05-31
0.5.96Review222026-05-30
0.5.95Review222026-05-30
0.5.93Review522026-05-28
0.5.94Review522026-05-28
0.5.91Review2652026-05-24
0.5.89Review2652026-05-24
0.5.90Review2652026-05-24

Block this in CI

PkgRadar gates wotann (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]