Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 291
- Versions published
- 49Established · −30% score
- First published
- Aug 2025
- Publisher
- encw.dev
Effective trust discount applied: −30% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Looks clean — keep monitoringNo high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@elliemae/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@elliemae/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
No high-signal static finding in the saved report.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk low · score 0 · status changed
Evidence
Static findings
No findings stored for this release.
Manifest
Package metadata
Scripts26
buildpui-cli pack -pbuild:devpui-cli packdocs:buildpui-doc-gen builddocs:servepui-doc-gen servedocs:startpui-doc-gen startdocs:versionpui-doc-gen versionlintpui-cli lintlint:fixpui-cli lint --fixlint:stagedlint-stagedreleasesemantic-releasesetuprimraf node_modules && rimraf pnpm-lock.yaml && pnpm istartpui-cli startstart:serverserve ./dist/public -l 3000start:testcross-env NODE_HTTP_SERVER_SSL_PASSPHRASE=uiplatform http-server --cors -c-1 -S -C ./ssl/cert.pem -K ./ssl/key.pem -p 443 --headers 'Cross-Origin-Opener-Policy: same-origin-allow-popups'storybookexit 0storybook:buildexit 0storybook:docsexit 0storybook:docs:buildexit 0storybook:prodexit 0testpui-cli test -ptest:debugpui-cli test --debugtest:fixpui-cli test -f -ptest:stagedjest --coverage --passWithNoTests --bail --findRelatedTeststest:watchjest --watchtscheckpui-cli tscheck --filesupgradencu -u && npm run setup
Dependencies2
logrocket~10.1.1logrocket-react~6.0.3