A collection of round filled Svelte icons with 1px radius and 1.5px stroke width, designed for use in Svelte applications.
No attack was identified. The install hook validates a caller-provided license key with the package’s vendor, while the inspected icon component renders SVG content.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook runs a license check.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkgThe check sends the caller-provided CENTRAL_LICENSE_KEY to the package vendor’s license endpoint with this package’s name and version.
license-check.jsView on unpkg · L14The check sends the caller-provided CENTRAL_LICENSE_KEY to the package vendor’s license endpoint with this package’s name and version.
license-check.jsThis report applies to @central-icons-svelte/round-filled-radius-1-stroke-1.5@1.2.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15The preinstall hook runs a license check.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgThe check sends the caller-provided CENTRAL_LICENSE_KEY to the package vendor’s license endpoint with this package’s name and version.
license-check.jsView on unpkg · L14The check sends the caller-provided CENTRAL_LICENSE_KEY to the package vendor’s license endpoint with this package’s name and version.
license-check.jsView on unpkg · L41Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg