Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 139,388Ubiquitous · −70% score
- Versions published
- 1,167Mature · −50% score
- First published
- May 2024
- Publisher
- bassel17
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@strapi/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@strapi/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
DNS / OAST exfiltration: matched "dns.lookup"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 15 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | DNS / OAST exfiltration | package/dist/server/services/file.js | matched "dns.lookup" | 30 |
| high | DNS / OAST exfiltration | package/dist/server/services/file.mjs | matched "dns.lookup" | 30 |
Manifest
Package metadata
Scripts14
buildrun -T npm-run-all clean --parallel build:code build:typesbuild:coderun -T rollup -cbuild:typesrun -T run-p build:types:server build:types:adminbuild:types:adminrun -T tsc -p admin/tsconfig.build.json --emitDeclarationOnlybuild:types:serverrun -T tsc -p server/tsconfig.build.json --emitDeclarationOnlycleanrun -T rimraf distlintrun -T eslint .test:frontrun -T cross-env IS_EE=true jest --config ./jest.config.front.jstest:front:watchrun -T cross-env IS_EE=true jest --config ./jest.config.front.js --watchtest:ts:backrun -T tsc --noEmit -p server/tsconfig.jsontest:ts:frontrun -T tsc -p admin/tsconfig.jsontest:unitrun -T jesttest:unit:watchrun -T jest --watchwatchrun -T rollup -c -w
Dependencies30
@mux/mux-player-react3.1.0@radix-ui/react-dialog1.0.5@radix-ui/react-toggle-group1.1.11@reduxjs/toolkit1.9.7@strapi/database5.47.0@strapi/design-system2.2.0@strapi/icons2.2.0@strapi/provider-upload-local5.47.0@strapi/utils5.47.0byte-size8.1.1cropperjs1.6.1date-fns2.30.0file-type21.3.4formik2.4.5fs-extra11.3.4immer9.0.21koa-range0.3.0koa-static5.0.0lodash4.18.1mime-types2.1.35prop-types^15.8.1qs6.15.0react-dnd16.0.1react-intl6.6.2react-query3.39.3react-redux8.1.3react-select5.8.0sharp0.33.5yup0.32.9zod3.25.67