6.4
gatsby
📦 npm PackageKyle Mathews
Blazing fast modern site generator for React
v5.16.1
Medium Risk6.4/10
Scanned June 1, 2026
Risk Flags
Developer identity not verified by the platform
Privacy policy doesn't match observed behavior
No privacy policy found despite requesting multiple permissions
5.9
Permissions
5.0
Developer
10.0
Data Privacy
2.0
Policy Match
Permissions (13)
Process execution library
dep:execa
Extended filesystem operations
dep:fs-extra
File pattern matching
dep:glob
HTTP client — makes network requests
dep:axios
HTTP fetch — makes network requests
dep:node-fetch
HTTP client — makes network requests
dep:got
WebSocket connections
dep:socket.io
HTTP server framework
dep:express
Reads environment variables from .env files
dep:dotenv
Runs code automatically after npm install: node scripts/postinstall.js
script:postinstall
Runs on install and before publish: cross-env NODE_ENV=production npm run build
script:prepare
Installs executable CLI commands
capability:binary
167 dependencies — large supply chain surface
dependencies:large
Developer
NameKyle Mathews
Verified PublisherUnverified
Known EntityNot recognized
Websitehttps://github.com/gatsbyjs/gatsby/tree/master/packages/gatsby#readme
Contactmathews.kyle@gmail.com
Data Flows
No external data transmission detected
This tool does not appear to send data to external servers.
Privacy Policy Analysis
Policy Status
No policy found
Policy Mismatches Found
- Package includes network libraries but no privacy documentation
Alternatives to Consider
Know what your tools are really doing.