A collection of round filled Solid icons with 1px radius and 1px stroke width, designed for use in Solid applications.
No confirmed attack surface was identified. The automatic network operation validates a designated product license key at a fixed service endpoint.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json runs license-check.js during preinstall and has no runtime self-dependency.
package.jsonView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads only CENTRAL_LICENSE_KEY and authenticates to the fixed Central Icons license endpoint.
license-check.jsView on unpkg · L14license-check.js reads only CENTRAL_LICENSE_KEY and authenticates to the fixed Central Icons license endpoint.
license-check.jsView on unpkg · L1The request body contains only the package name and version; the complete hook performs no file access, shell execution, or remote code execution.
license-check.jsView on unpkg · L19This report applies to @central-icons-solid/round-filled-radius-1-stroke-1@1.2.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14package.json runs license-check.js during preinstall and has no runtime self-dependency.
package.jsonView on unpkg · L14license-check.js reads only CENTRAL_LICENSE_KEY and authenticates to the fixed Central Icons license endpoint.
license-check.jsView on unpkg · L1license-check.js reads only CENTRAL_LICENSE_KEY and authenticates to the fixed Central Icons license endpoint.
license-check.jsView on unpkg · L14The request body contains only the package name and version; the complete hook performs no file access, shell execution, or remote code execution.
license-check.jsView on unpkg · L19Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg