No confirmed malicious attack surface. Runtime networking is application-facing CMS/form functionality; build writes are limited to dist manifest artifacts.
Static reason
No blocking static signals were detected.
Trigger
Consumer imports/configures the package or explicitly runs its build/publish workflow.
Impact
No credential harvesting, covert exfiltration, persistence, or install-time mutation found.
Mechanism
Payload CMS UI configuration, rendering, and form support
Rationale
Source inspection found no install-time execution or malicious chain. Network, environment, and filesystem primitives are package-aligned CMS/runtime and build features.
Evidence
package.jsondist/uims/resolver/viewResolver.jsdist/react/components/Form/FormClientWrapper.jsdist/generate-manifest.jsdist/generatePreviewPath.jsdist/utils/generateCssVars.js