Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 37Established · −30% score
- First published
- Oct 2025
- Publisher
- GitHub ActionsTrusted automation · −70% score
Effective trust discount applied: −70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@zone-eu/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@zone-eu/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Remote Payload: matched "curl "
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 28 · status changed
Evidence
Static findings
9 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/setup/01_install_commits.sh | matched "curl " | 12 |
| medium | Remote Payload | package/setup/04_install_import_keys.sh | matched "curl " | 12 |
| medium | Remote Payload | package/setup/05_install_packages.sh | matched "wget " | 12 |
| medium | Remote Payload | package/setup/13_install_ssl_certs.sh | matched "wget " | 12 |
| medium | Remote Payload | package/setup/15_install_deploy.sh | matched "curl " | 12 |
| medium | Remote Payload | package/setup/get_install.sh | matched "raw.githubusercontent.com" | 12 |
| medium | Remote Payload | package/setup/install.sh | matched "curl " | 12 |
Show all 9 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/setup/01_install_commits.sh | matched "curl " | 12 |
| medium | Remote Payload | package/setup/04_install_import_keys.sh | matched "curl " | 12 |
| medium | Remote Payload | package/setup/05_install_packages.sh | matched "wget " | 12 |
| medium | Remote Payload | package/setup/13_install_ssl_certs.sh | matched "wget " | 12 |
| medium | Remote Payload | package/setup/15_install_deploy.sh | matched "curl " | 12 |
| medium | Remote Payload | package/setup/get_install.sh | matched "raw.githubusercontent.com" | 12 |
| medium | Remote Payload | package/setup/install.sh | matched "curl " | 12 |
| low | Credential file access | package/setup/04_install_import_keys.sh | matched ".ssh/" | 5 |
| low | Credential file access | package/setup/15_install_deploy.sh | matched ".ssh/" | 5 |
Manifest
Package metadata
Scripts10
apidocapidoc -i lib/api/ -o docs/api/generate-api-docsGENERATE_API_DOCS=true REGENERATE_API_DOCS=true node server.jsprintconfNODE_CONFIG_ONLY=true npm startruncinpm run printconf && npm run runtestruntestNODE_ENV=test gruntshowNODE_CONFIG_ONLY=true node server.jsstartnode server.jstestmongosh --eval 'db.dropDatabase()' wildduck-test && redis-cli -n 13 flushdb && npm run runtesttest:protoNODE_ENV=test grunt protoupdaterm -rf node_modules package-lock.json && ncu -u && npm install
Dependencies64
@fidm/x5091.2.1@opensearch-project/opensearch3.6.0@phc/pbkdf21.1.14@postalsys/vmc1.1.4@root/acme3.1.0@root/csr0.8.1@zone-eu/mailsplit5.4.11@zone-eu/mobileconfig2.4.6@zone-eu/seq-index1.1.5@zone-eu/smime-js0.1.0@zone-eu/wild-config1.7.5@zone-eu/wild-plugins1.0.6@zone-eu/zone-mta3.10.16accesscontrol2.2.1axios1.16.1base32.js0.1.0bcryptjs3.0.3bson7.2.0bullmq5.77.3fido2-lib3.5.9gelf2.0.1generate-password1.7.1hash-wasm4.12.0he1.2.0html-to-text10.0.0http-parser-js0.5.10humanname0.2.2iconv-lite0.7.2ioredfour1.4.1ioredis5.10.1- …and 34 more.