A collection of square outlined Svelte icons with 0px radius and 1px stroke width, designed for use in Svelte applications.
No attack surface was established. The install-time license request sends the caller-supplied Central Icons key only to the vendor license endpoint, and icon modules are static Svelte SVG components.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json defines a Svelte icon package whose only install script is preinstall running node ./license-check.js, with no bin entry or dependency on itself.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and, if missing, throws before any request; otherwise it POSTs that key as a bearer token plus the package name and version to https://centralicons.com/license/check.
license-check.jsView on unpkg · L1license-check.js reads CENTRAL_LICENSE_KEY and, if missing, throws before any request; otherwise it POSTs that key as a bearer token plus the package name and version to https://centralicons.com/license/check.
This report applies to @central-icons-svelte/square-outlined-radius-0-stroke-1@1.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15package.json defines a Svelte icon package whose only install script is preinstall running node ./license-check.js, with no bin entry or dependency on itself.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and, if missing, throws before any request; otherwise it POSTs that key as a bearer token plus the package name and version to https://centralicons.com/license/check.
license-check.jsView on unpkg · L1license-check.js reads CENTRAL_LICENSE_KEY and, if missing, throws before any request; otherwise it POSTs that key as a bearer token plus the package name and version to https://centralicons.com/license/check.
license-check.jsView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg