A collection of round filled Solid icons with 1px radius and 1px stroke width, designed for use in Solid applications.
No attack was identified. The preinstall hook performs a package-specific license check with the package vendor.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest runs license-check.js during preinstall; its other listed scripts are build, prepublishOnly, and lint.
package.jsonView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads the package-specific license key from the environment and sends it to the matching Central Icons license-check endpoint with this package name and version.
license-check.jsView on unpkg · L1license-check.js reads the package-specific license key from the environment and sends it to the matching Central Icons license-check endpoint with this package name and version.
license-check.jsView on unpkg · L14The script checks the service response and catches errors; inspected source shows no unrelated data collection or package file mutation.
license-check.jsView on unpkg · L37This report applies to @central-icons-solid/round-filled-radius-1-stroke-1@1.2.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14The manifest runs license-check.js during preinstall; its other listed scripts are build, prepublishOnly, and lint.
package.jsonView on unpkg · L13license-check.js reads the package-specific license key from the environment and sends it to the matching Central Icons license-check endpoint with this package name and version.
license-check.jsView on unpkg · L1license-check.js reads the package-specific license key from the environment and sends it to the matching Central Icons license-check endpoint with this package name and version.
license-check.jsView on unpkg · L14The script checks the service response and catches errors; inspected source shows no unrelated data collection or package file mutation.
license-check.jsView on unpkg · L37Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg