Package evidence
[email protected]
Install-time lifecycle script: postinstall="grep -qF 'src/styles/_js_variables.scss' ../../.gitignore || echo 'src/styles/_js_variables.scss' >> ../../.gitignore"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 86
- Versions published
- 746Mature · −50% score
- First published
- Oct 2020
- Publisher
- tofandel
Effective trust discount applied: −50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Install-time lifecycle script: postinstall="grep -qF 'src/styles/_js_variables.scss' ../../.gitignore || echo 'src/styles/_js_variables.scss' >> ../../.gitignore"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 1 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
No high-signal findings — see all findings below.
Show all 1 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| low | Install-time lifecycle script | package.json | postinstall="grep -qF 'src/styles/_js_variables.scss' ../../.gitignore || echo 'src/styles/_js_variables.scss' >> ../../.gitignore" | 5 |
Manifest
Package metadata
Scripts8
buildvue-cli-service build --target lib --name rewart-frontend-library src/main.jsbuild:devvue-cli-service build --target lib --mode development --name rewart-frontend-library src/main.jslintvue-cli-service lintlint:fixvue-cli-service lint --fixpostinstallgrep -qF 'src/styles/_js_variables.scss' ../../.gitignore || echo 'src/styles/_js_variables.scss' >> ../../.gitignoresemantic-releasesemantic-releasetestnpm run test:unit --test:unitvue-cli-service test:unit
Dependencies47
@hcaptcha/vue-hcaptcha~1.3.0@mdi/js^7.0.0@prerenderer/renderer-puppeteer^1.1.4@prerenderer/webpack-plugin^5.3.0@semantic-release/git^10.0.1@sentry/vue^10.0.0@tofandel/debounce-promise^5.1.11@vuex-orm/core^0.36.4axios^1.0.0axios-mock-adapter^2.1.0compression-webpack-plugin^11.0.0deepmerge^4.2.2dotenv^17.0.0env-ci^11.0.0favicons^7.0.2favicons-webpack-plugin~6.0.0filepond~4.32.0filepond-plugin-file-rename~1.1.8filepond-plugin-file-validate-size~2.2.5filepond-plugin-file-validate-type~1.2.6filepond-plugin-image-exif-orientation~1.0.11filepond-plugin-image-preview~4.6.10filepond-plugin-image-resize~2.0.10filepond-plugin-image-transform~3.8.7filepond-plugin-image-validate-size~1.2.6html-webpack-plugin^5.5.0json2scss-map^1.5.1lint-staged~16.2.7object-hash^3.0.0object-to-formdata~4.5.1- …and 17 more.
Optional dependencies23
@babel/eslint-parser~7.28.0@babel/plugin-proposal-export-default-from~7.27.0@babel/plugin-transform-class-properties~7.27.0@babel/plugin-transform-private-methods~7.27.0@babel/plugin-transform-private-property-in-object~7.27.0@vue/cli-plugin-babel~5.0.8@vue/cli-plugin-eslint~5.0.8@vue/cli-service~5.0.8@vue/eslint-config-standard~8.0.1@vue/preload-webpack-plugin~2.0.0eslint-plugin-es~4.1.0eslint-plugin-import~2.32.0eslint-plugin-n~17.21.0eslint-plugin-promise~7.2.0eslint-plugin-vue~9.33.0register-service-worker^1.7.2vue-cli-plugin-vuetify~2.5.5vue-meta^2.4.0webpack-preprocessor-loader~1.3.0workbox-core~7.3.0workbox-precaching~7.3.0workbox-routing~7.3.0workbox-strategies~7.3.0