Package evidence
@webpresso/[email protected]
Known Indicator Filename: package/dist/esm/cli/commands/blueprint/execution.js
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 2
- First published
- May 2026
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@webpresso/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@webpresso/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Known Indicator Filename: package/dist/esm/cli/commands/blueprint/execution.js
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 27 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Known Indicator Filename | package/dist/esm/cli/commands/blueprint/execution.js | package/dist/esm/cli/commands/blueprint/execution.js | 45 |
| high | Known Indicator Filename | package/dist/esm/e2e/execution.js | package/dist/esm/e2e/execution.js | 45 |
Manifest
Package metadata
Scripts37
audit:secret-provider-quarantinebun scripts/audit-secret-provider-quarantine.tsaudits:checkWP_SKIP_UPDATE_CHECK=1 wp audit guardrails && vp run hooks:doctor:ciblueprints:checkWP_SKIP_UPDATE_CHECK=1 wp audit blueprint-lifecyclebuildtshy && vp run chmod-bins && vp run link-self-binscatalog:checkWP_SKIP_UPDATE_CHECK=1 wp audit catalog-driftchangesetchangesetchangeset:statuschangeset statuschmod-binsbun scripts/chmod-bins.tsdev:linkbun scripts/link-edge-local.tsdocs:checkWP_SKIP_UPDATE_CHECK=1 wp audit docs-frontmatterevalbun src/runners/evals/index.tsformatWP_SKIP_UPDATE_CHECK=1 wp formatformat:checkWP_SKIP_UPDATE_CHECK=1 wp format --checkgenerate-skillsbun src/build/generate-skills-dir.tshooks:doctorWP_SKIP_UPDATE_CHECK=1 wp hooks doctorhooks:doctor:ciWP_SKIP_UPDATE_CHECK=1 wp hooks doctor --skip-mcpimports:checkWP_SKIP_UPDATE_CHECK=1 wp audit no-relative-parent-importslicense:checkWP_SKIP_UPDATE_CHECK=1 bun src/cli/cli.ts audit open-source-licenses && bash scripts/verify-no-context-mode.shlink-self-binsbun scripts/link-self-bins.tslintvp lintlint:fixvp lint --fixlint:pkgpublint && attw --pack . && (command -v claude >/dev/null 2>&1 && claude plugin validate . || true)postbuildvp run generate-skillspostpackbun src/build/package-manifest.ts restoreprepackbun src/build/package-manifest.ts preparepreparehuskypublic:readinessbun scripts/public-readiness.tsqavp run build && vp run typecheck && vp run lint && vp run format:check && vp run test && vp run lint:pkg && vp run audits:checkrelease:publishpnpm run build && npm publish --provenance --access publicsetup:agentwp setup- …and 7 more.
Dependencies20
@manypkg/find-root^3.1.0@modelcontextprotocol/sdk^1.29.0@vitejs/plugin-react^6.0.1better-sqlite3^12.9.0cac^7.0.0env-paths^4.0.0glob^13.0.6gray-matter^4.0.3js-yaml^4.1.0ora^8.2.0proper-lockfile^4.1.2remark^15.0.1remark-frontmatter^5.0.0remark-validate-links^13.1.0rulesync8.15.1ts-pattern^5.9.0vite-plus^0.1.19yaml^2.8.1zod^4.4.3zod-to-json-schema^3.25.2