PkgRadar

Package evidence

[email protected]

no findings

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
32
Versions published
7
First published
May 2026
Publisher
vancura

Recommended action

Looks clean — keep monitoring

No high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Publishervancura
Artifact bytes126,424
Previous version1.0.4
Published2026-05-21T13:18:12.126Z
SHA-256de5a9bdb19019d7403eb3ce9665d13a1e119cf9b2c1d891de94f8b0744c1d1c9

Why flagged

What the scanner saw

No high-signal static finding in the saved report.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

low
Last checked
lowRisk
0Score
1.0.5Version
Status history (1 event)
  1. newavailable · risk low · score 0 · status changed

Evidence

Static findings

No findings stored for this release.

Manifest

Package metadata

Scripts35
  • benchvitest bench
  • bench:jsonvitest bench --outputJson benchmark-results.json
  • buildvite build
  • build:check-declarationsnode scripts/check-declaration-tooling.mjs
  • cleanrm -rf dist node_modules/.vite
  • convert-fontnode scripts/convert-bmfont.mjs
  • formatbiome format --write . && prettier --write "**/*.{md,mdx,yml,yaml}"
  • format:biomebiome format --write .
  • format:checkbiome check . && prettier --check "**/*.{md,mdx,yml,yaml}"
  • format:prettierprettier --write "**/*.{md,mdx,yml,yaml}"
  • knipknip
  • knip:fixknip --fix
  • linteslint .
  • lint:fixeslint . --fix
  • preflightpnpm format:check && pnpm lint && pnpm typecheck && pnpm spellcheck && pnpm knip && pnpm test:unit && pnpm test:declarations
  • preparehusky
  • prepublishOnlypnpm run build
  • releasepnpm build && pnpm publish
  • security:auditpnpm audit --audit-level=moderate
  • security:audit:fixpnpm audit --fix
  • security:audit:prodpnpm audit --prod --audit-level=moderate
  • security:mcp-preflightnode scripts/security/mcp-preflight.mjs
  • spellcheckcspell "src/**/*.{ts,md,mdx}" "docs/**/*.{md,mdx}" "README.md" --no-progress
  • system-font:convertnode scripts/convert-system-font.mjs
  • system-font:exportnode scripts/export-system-font.mjs
  • testvitest run
  • test:declarationsnode --test scripts/check-declaration-tooling.test.mjs
  • test:security-preflightnode --test scripts/security/mcp-preflight.test.mjs
  • test:unitvitest run
  • test:unit:coveragevitest run --coverage
  • …and 5 more.