No confirmed malicious attack surface. Runtime code is local Solid hydration orchestration and wrappers around declared TanStack dependencies.
Static reason
No blocking static signals were detected.
Trigger
Application imports and uses the exported Solid client/hydration APIs.
Impact
No credential harvesting, persistence, code execution, destructive action, or exfiltration established.
Mechanism
Client-side hydration rendering and lifecycle coordination.
Rationale
Static source inspection shows a normal TanStack Solid client hydration package with no install-time execution or malicious behavior. The wildcard Vite development dependency is not an attack chain in this package source.
Evidence
package.jsonsrc/GenericHydrate.tsxsrc/hydrateStart.tssrc/hydration/generic.tsdist/esm/index.jsREADME.mdsrc/Hydrate.tsxsrc/StartClient.tsxsrc/hydration/idle.tssrc/hydration/load.tsxsrc/hydration/never.tssrc/hydration/visible.tsxdist/esm/GenericHydrate.js