No confirmed attack surface is established. Installation has no lifecycle hook, and runtime code only registers Tailwind styling rules.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgThe release-notes helper only reads the package changelog and prints matching text.
scripts/release-notes.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThe release-channel helper only parses a version string and prints a release tag.
scripts/release-channel.jsView on unpkg · L10The manifest has no install lifecycle hook and declares only the form plugin entry point.
package.jsonView on unpkg · L20The runtime entry point builds Tailwind form styling rules; it contains no command execution, file access, or network request.
src/index.jsView on unpkg · L358This report applies to tailwind-form-kit@0.5.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgThe release-notes helper only reads the package changelog and prints matching text.
scripts/release-notes.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThe release-channel helper only parses a version string and prints a release tag.
scripts/release-channel.jsView on unpkg · L10The manifest has no install lifecycle hook and declares only the form plugin entry point.
package.jsonView on unpkg · L20The runtime entry point builds Tailwind form styling rules; it contains no command execution, file access, or network request.
src/index.jsView on unpkg · L358