Fetch and cache CDN images locally for web projects
No attack was identified. The source implements a caller-invoked HTTPS download to a caller-selected file.
package.json selects index.js and declares no lifecycle scripts or dependencies.
package.jsonView on unpkg · L2The exported download function requests the caller-supplied HTTPS URL and writes the response to the caller-supplied destination.
index.jsView on unpkg · L4The entrypoint exports functions without invoking downloads; it contains no credential harvesting, shell execution, or dynamic code loading.
index.jsView on unpkg · L14This report applies to cdn-img-fetch@1.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
package.json selects index.js and declares no lifecycle scripts or dependencies.
package.jsonView on unpkg · L2The exported download function requests the caller-supplied HTTPS URL and writes the response to the caller-supplied destination.
index.jsView on unpkg · L4The entrypoint exports functions without invoking downloads; it contains no credential harvesting, shell execution, or dynamic code loading.
index.jsView on unpkg · L14