A collection of round outlined Svelte icons with 1px radius and 1.5px stroke width, designed for use in Svelte applications.
No attack surface was established. The install hook sends the package license key to the vendor license endpoint and icon modules only draw SVG.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall runs only preinstall node ./license-check.js. Other scripts are build, prepublishOnly, and lint. The sole dependency is a Svelte peer.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgIcon3d.svelte only imports CentralIconBase and renders static SVG circles. The package entry re-exports icon components.
Icon3d/Icon3d.svelteView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and throws if it is missing. It does not read other environment variables or files.
license-check.jsView on unpkg · L1This report applies to @central-icons-svelte/round-outlined-radius-1-stroke-1.5@1.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15Install runs only preinstall node ./license-check.js. Other scripts are build, prepublishOnly, and lint. The sole dependency is a Svelte peer.
package.jsonView on unpkg · L14Icon3d.svelte only imports CentralIconBase and renders static SVG circles. The package entry re-exports icon components.
Icon3d/Icon3d.svelteView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and throws if it is missing. It does not read other environment variables or files.
license-check.jsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg