PkgRadar

PyPI · pypi.org

yourmemory

Remote Payload: matched "github.com/explosion/spacy-models/releases/download"

Why PkgRadar flagged 1.4.51

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/explosion/spacy-models/releases/download" · yourmemory-1.4.51/memory_mcp.py
mediumRemote Payloadmatched "curl " · yourmemory-1.4.51/src/hook_templates/yourmemory_recall.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.51Review242026-06-16
1.4.50Review242026-06-15
1.4.49Review242026-06-15
1.4.48Review122026-06-14
1.4.47Review122026-06-12
1.4.46Review122026-06-12
1.4.45Review122026-06-11
1.4.44Review122026-06-10
1.4.43Review122026-06-10
1.4.42Review122026-06-10
1.4.41Review122026-06-10
1.4.40Review122026-06-10
1.4.39Review122026-06-10
1.4.38Review122026-06-09
1.4.37Review122026-06-09
1.4.36Review122026-06-08
1.4.35Review122026-06-07
1.4.34Review122026-06-07
1.4.33Review122026-06-07
1.4.32Review122026-06-07
1.4.31Review122026-06-07
1.4.30Review122026-05-30
1.4.29Review122026-05-28
1.4.28Review122026-05-28
1.4.27Review122026-05-28

Block this in CI

PkgRadar gates yourmemory (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi yourmemory==1.4.51