No confirmed malicious attack surface is established. The package is a Tailwind form-styling plugin with explicit developer release helpers.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgThe flagged release-notes utility only reads CHANGELOG.md and prints a selected section.
scripts/release-notes.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThe flagged release-channel utility only parses a version string and prints a channel.
scripts/release-channel.jsView on unpkg · L10The manifest has no preinstall, install, or postinstall hook; its release utilities require explicit npm-script invocation.
package.jsonView on unpkg · L20The runtime entry point creates Tailwind form-style rules and exports the plugin.
src/index.jsView on unpkg · L12This report applies to tailwindcss-form-kit@0.5.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgThe flagged release-notes utility only reads CHANGELOG.md and prints a selected section.
scripts/release-notes.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThe flagged release-channel utility only parses a version string and prints a channel.
scripts/release-channel.jsView on unpkg · L10The manifest has no preinstall, install, or postinstall hook; its release utilities require explicit npm-script invocation.
package.jsonView on unpkg · L20The runtime entry point creates Tailwind form-style rules and exports the plugin.
src/index.jsView on unpkg · L12