Loading npm security reports…
Parsers Py/JS
No malicious payload or exfiltration path was found. The only meaningful lifecycle risk is prepare-time local VCS hook setup via Husky.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L58Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L58