Package evidence
@postermywall/[email protected]
Remote Dependency Spec: devDependencies.babel-plugin-transform-imports="git+https://[email protected]/fabricjs/babel-plugin-transform-imports.git"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 345
- Versions published
- 60Mature · −50% score
- First published
- Jun 2024
- Publisher
- azmeer250
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@postermywall/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@postermywall/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Dependency Spec: devDependencies.babel-plugin-transform-imports="git+https://[email protected]/fabricjs/babel-plugin-transform-imports.git"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 4 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Dependency Spec | package.json | devDependencies.babel-plugin-transform-imports="git+https://[email protected]/fabricjs/babel-plugin-transform-imports.git" | 8 |
Manifest
Package metadata
Scripts25
buildnpm run cli -- buildbuild:fastnpm run build -- -fclinode ./scripts/index.mjscoverage:mergenyc merge coveragefiles .nyc_output/merged-coverage.jsoncoverage:reportnyc report --skip-full=true --reporter=lcov --reporter=text --reporter=text-summarycoverage:report:cinyc report --reporter=text-summarydevnpm run cli -- devdocstypedocexportnpm run cli -- website exportlinteslint src extensionslocal-serverserve ./ -l tcp://localhost:8080playwright:typechecktsc -p ./e2e/tsconfig.json --noEmitprettier:checkprettier --check .prettier:writeprettier --write .releasenpm publish --access public --tag pmwsandboxnpm run sandboxscript -- sandboxsandboxscriptnode ./scripts/sandbox.mjsstartnpm run sandboxscript -- starttest:e2enpm run playwright:typecheck && playwright testtest:vitestvitest --run --project unit-nodetest:vitest:allvitest --runtest:vitest:chromiumvitest --run --project unit-chromiumtest:vitest:coveragevitest --run --coverage --project unit-nodetest:vitest:coverage:watchnpm run test:vitest --coverage=truetest:vitest:firefoxvitest --run --project unit-firefox
Dependencies1
westures^1.1.1
Optional dependencies2
canvas^3.2.0jsdom^26.1.0