No confirmed attack surface is established. Installation has no lifecycle hook, and the package runtime supplies Tailwind form styles.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgThe release-notes script reads only the package changelog and prints matching text.
scripts/release-notes.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThe release-channel script derives and prints an npm release tag from a version string.
scripts/release-channel.jsView on unpkg · L10The manifest has no install lifecycle hook; its flagged scripts are explicit development and release commands.
package.jsonView on unpkg · L20This report applies to tailwindcss-contact-forms@0.5.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgThe release-notes script reads only the package changelog and prints matching text.
scripts/release-notes.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThe release-channel script derives and prints an npm release tag from a version string.
scripts/release-channel.jsView on unpkg · L10The manifest has no install lifecycle hook; its flagged scripts are explicit development and release commands.
package.jsonView on unpkg · L20