A collection of square filled Svelte icons with 0px radius and 1.5px stroke width, designed for use in Svelte applications.
No malicious attack surface was identified. The only install-time activity is a fixed-endpoint license validation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook runs only the included license-check.js file.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkgThe checker reads the named Central license-key environment variable and sends it as Bearer authentication to a fixed license-check endpoint with only package and version metadata.
license-check.jsView on unpkg · L1The checker reads the named Central license-key environment variable and sends it as Bearer authentication to a fixed license-check endpoint with only package and version metadata.
This report applies to @central-icons-svelte/square-filled-radius-0-stroke-1.5@1.1.321.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15The preinstall hook runs only the included license-check.js file.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgThe checker reads the named Central license-key environment variable and sends it as Bearer authentication to a fixed license-check endpoint with only package and version metadata.
license-check.jsView on unpkg · L1The checker reads the named Central license-key environment variable and sends it as Bearer authentication to a fixed license-check endpoint with only package and version metadata.
license-check.jsView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg