A collection of round outlined Solid icons with 1px radius and 1px stroke width, designed for use in Solid applications.
No confirmed attack was identified. The install hook authenticates a package-specific license against a fixed vendor endpoint.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json runs license-check.js during preinstall and declares only a Solid peer dependency, with no runtime self-dependency.
package.jsonView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js sends a dedicated license key to the fixed https://centralicons.com/license/check endpoint for authentication.
license-check.jsView on unpkg · L14The credential comes only from CENTRAL_LICENSE_KEY; the hook does not harvest files or unrelated environment variables.
license-check.jsView on unpkg · L1The runtime entrypoint exports icon components, and the shared helper constructs SVG attributes.
index.jsxView on unpkg · L1This report applies to @central-icons-solid/round-outlined-radius-1-stroke-1@1.2.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14package.json runs license-check.js during preinstall and declares only a Solid peer dependency, with no runtime self-dependency.
package.jsonView on unpkg · L14The runtime entrypoint exports icon components, and the shared helper constructs SVG attributes.
index.jsxView on unpkg · L1The credential comes only from CENTRAL_LICENSE_KEY; the hook does not harvest files or unrelated environment variables.
license-check.jsView on unpkg · L1license-check.js sends a dedicated license key to the fixed https://centralicons.com/license/check endpoint for authentication.
license-check.jsView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg