Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@drumee/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@drumee/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "WGET "
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 15 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/lib/lex/constants.js | matched "WGET " | 12 |
Show all 2 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/lib/lex/constants.js | matched "WGET " | 12 |
| low | Obfuscation | package/lib/subtleCrypto.js | matched "atob(" | 3 |
Manifest
Package metadata
Scripts9
releasegit push && npm publish --access public && npm version patchshow:cachenode lib/test/cache.jsshow:sysEnvnode lib/test/sysEnv.jstestnpm run test:modules && npm run test:db && npm run test:cachetest:cryptonode lib/test/subtleCrypto.jstest:dbnode lib/test/db.jstest:emailnode lib/test/email.jstest:modulesnode lib/test/cache.jstest:templatenode lib/test/template.js
Dependencies13
backbone^1.4.0file-type^21.3.3googleapis^144.0.0https^1.0.0istextorbinary^9.5.0jsonfile^5.0.0lodash^4.17.21mariadb^3.5.2nodemailer^8.0.5redis^4.6.6sanitize-html^2.10.0shelljs^0.8.5syslog-client-tls^1.2.1