A state management library for Clicktap reference frontend.
No malicious attack surface was identified. The install hook is a nested-install guard, and the network calls are exposed authentication/request functionality.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe preinstall hook only rejects a nested install with an explanatory error; it does not install dependencies, mutate agent configuration, or contact a network.
package.jsonView on unpkg · L92Authentication requests use the caller-provided client endpoint and include browser credentials as part of the package's auth flow.
AuthProvider-B8dXFZk6.mjsView on unpkg · L180The shared request helper forwards its supplied URL and options to fetch.
request-VRlU6wWt.mjsView on unpkg · L1This report applies to @clicktap/state@3.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
The preinstall hook only rejects a nested install with an explanatory error; it does not install dependencies, mutate agent configuration, or contact a network.
package.jsonView on unpkg · L92Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L93Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L93Authentication requests use the caller-provided client endpoint and include browser credentials as part of the package's auth flow.
AuthProvider-B8dXFZk6.mjsView on unpkg · L180The shared request helper forwards its supplied URL and options to fetch.
request-VRlU6wWt.mjsView on unpkg · L1