A state management library for Clicktap reference frontend.
No attack was identified. The preinstall guard blocks nested installation, and the inspected authentication requests use configured service endpoints.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpackage.json defines a preinstall guard that rejects nested installs and directs installation from the monorepo root.
package.jsonView on unpkg · L97AuthProvider requires caller-provided client and server endpoints for refresh requests.
AuthProvider-BCmw2hiQ.mjsView on unpkg · L137Refresh requests use the configured endpoint with credentials included; the request helper sends to its supplied URL.
AuthProvider-BCmw2hiQ.mjsView on unpkg · L163Refresh requests use the configured endpoint with credentials included; the request helper sends to its supplied URL.
request-DNOy04EM.mjsView on unpkg · L8This report applies to @clicktap/state@3.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
package.json defines a preinstall guard that rejects nested installs and directs installation from the monorepo root.
package.jsonView on unpkg · L97Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L98Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L98AuthProvider requires caller-provided client and server endpoints for refresh requests.
AuthProvider-BCmw2hiQ.mjsView on unpkg · L137Refresh requests use the configured endpoint with credentials included; the request helper sends to its supplied URL.
AuthProvider-BCmw2hiQ.mjsView on unpkg · L163Refresh requests use the configured endpoint with credentials included; the request helper sends to its supplied URL.
request-DNOy04EM.mjsView on unpkg · L8