Package evidence
@convex-dev/[email protected]
Install-time lifecycle script: postinstall="echo '\\nπ¦ @convex-dev/static-hosting installed!\\n\\n π Quick Setup (Interactive):\\n npx @convex-dev/static-hosting setup\\n\\n π€ For LLMs: See INTEGRATION.md for complete integration instructions\\n π Manual Setup: npx @convex-dev/static-hosting init\\n'"
Trust signals
Why this verdict
PkgRadar discounts a releaseβs score when public reputation argues against novel malware. The verdict above already reflects these β the panel just explains what was applied.
- Weekly downloads
- 2,633Niche Β· β30% score
- Versions published
- 4
- First published
- Feb 2026
- Publisher
- sethconvex
Effective trust discount applied: β30% (max across signals β discounts donβt stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl Β· GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@convex-dev/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@convex-dev/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Install-time lifecycle script: postinstall="echo '\\nπ¦ @convex-dev/static-hosting installed!\\n\\n π Quick Setup (Interactive):\\n npx @convex-dev/static-hosting setup\\n\\n π€ For LLMs: See INTEGRATION.md for complete integration instructions\\n π Manual Setup: npx @convex-dev/static-hosting init\\n'"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new β available Β· risk review Β· score 3 Β· status changed
Evidence
Static findings
1 static Β· 0 from release diff Β· showing high-signal first.
No high-signal findings β see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Install-time lifecycle script | package.json | postinstall="echo '\\nπ¦ @convex-dev/static-hosting installed!\\n\\n π Quick Setup (Interactive):\\n npx @convex-dev/static-hosting setup\\n\\n π€ For LLMs: See INTEGRATION.md for complete integration instructions\\n π Manual Setup: npx @convex-dev/static-hosting init\\n'" | 5 |
Manifest
Package metadata
Scripts23
allrun-p -r 'dev:*' 'test:watch'alphanpm version prerelease --preid alpha && npm publish --tag alpha && git push --follow-tagsbuildtsc --project ./tsconfig.build.jsonbuild:cleanrm -rf dist *.tsbuildinfo && npm run build:codegenbuild:codegennpx convex codegen --component-dir ./src/component && npm run buildbuild:examplecd example && vite builddeploy:staticnpm run build:example && npm run upload:staticdevrun-p -r 'dev:*'dev:backendconvex dev --typecheck-componentsdev:buildchokidar 'tsconfig*.json' 'src/**/*.ts' -i '**/*.test.ts' -c 'npm run build:codegen' --initialdev:frontendcd example && vite --clearScreen falselinteslint .postinstallecho '\nπ¦ @convex-dev/static-hosting installed!\n\n π Quick Setup (Interactive):\n npx @convex-dev/static-hosting setup\n\n π€ For LLMs: See INTEGRATION.md for complete integration instructions\n π Manual Setup: npx @convex-dev/static-hosting init\n'predevpath-exists .env.local dist || (npm run build && convex dev --once)preversionnpm ci && npm run build:clean && run-p test lint typecheckreleasenpm version patch && npm publish && git push --follow-tagstestvitest run --typechecktest:coveragevitest run --coverage --coverage.reporter=texttest:debugvitest --inspect-brk --no-file-parallelismtest:watchvitest --typecheck --clearScreen falsetypechecktsc --noEmit && tsc -p example && tsc -p example/convexupload:staticnode dist/cli/index.js upload --dist ./example/dist --component staticHostingversionvim -c 'normal o' -c 'normal o## '$npm_package_version CHANGELOG.md && prettier -w CHANGELOG.md && git add CHANGELOG.md