nuget pack csproj check: flags PackageLicenseUrl (NU5125), PackageIconUrl (NU5048), non-SPDX licence expressions, unpacked icon/readme/licence files and net8.0/net9.0 (end of support 2026-11-10), with the fix line. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
Scan every project in the workspace and export a dated pack-readiness report per package; a team key adds a CI gate that fails a release on any error
One payment, one licence key for this tool. The key is shown right after payment.
nuget.org does not support permanent deletion of packages: a version pushed with a bad licence or a missing readme can only be unlisted, and it still restores by exact version.
Buy the full version — $29· ReadyStack
Real numbers from this tool, line by line.

Six NuGet pack issues turned up in Acme.Invoicing.csproj, the project file of a .NET library author publishing an invoice builder to nuget.org: two errors and four warnings, checked on September 30, 2026.
Microsoft's .NET support policy lists .NET 8 (LTS) and .NET 9 (STS) with end of support on November 10, 2026. .NET 10 is LTS with end of support on November 14, 2028.
On the metadata side, NU5125 says: "The 'licenseUrl' element will be deprecated. Consider using the 'license' element instead." NU5048 says the same about PackageIconUrl and PackageIcon. The nuspec reference adds that nuget.org "only accepts license expressions that are approved by the Open Source Initiative or the Free Software Foundation". The MSBuild pack reference says the icon, readme and licence file must each be packed explicitly.
| Line | csproj line | Fix | Severity |
|---|---|---|---|
| 4 | <TargetFrameworks> …net8.0 | net10.0, LTS to November 14, 2028 | warning |
| 4 | <TargetFrameworks> …net9.0 | net10.0, LTS to November 14, 2028 | warning |
| 9 | <PackageLicenseUrl>…/LICENSE | delete it, keep one licence property | warning |
| 10 | <PackageLicenseExpression>Apache 2.0 | <PackageLicenseExpression>Apache-2.0 | error |
| 11 | <PackageIconUrl>…/icon.png | <PackageIcon>icon.png + Pack="true" | warning |
| 12 | <PackageReadmeFile>README.md, not packed | <None Include="README.md" Pack="true"> | error |
"Apache 2.0" is not an SPDX identifier; Apache-2.0 is. The readme is named in PackageReadmeFile but no item packs it. The four warnings are the two target frameworks, the deprecated licence URL left next to the new expression, and an icon URL with no embedded icon.
Change the check date to November 10, 2026 or later and the same file returns four errors and two warnings, because net8.0 and net9.0 have then ended support.
dotnet pack does print NU5125 and NU5048, but as warnings, after a full build, one project at a time. A default build still passes, so in a CI log they scroll past. It is silent on the November 10 date. And nuget.org does not support permanent deletion of packages: a version pushed with the wrong licence can only be unlisted, and it still restores for anyone who pins it. The fix costs a version number.
NuGet Pack Gate reads .csproj, .fsproj, .vbproj and Directory.Build.props against 10 rules: PackageLicenseUrl, PackageIconUrl without PackageIcon, invalid SPDX expressions, licences nuget.org does not accept (BUSL-1.1, SSPL-1.0, Elastic-2.0, PolyForm, CC-BY-NC), licence expression and licence file both set, unpacked licence, icon and readme files, net8.0 and net9.0, and older targets such as net6.0. Each finding names the line, the fix and its Microsoft source page. The fixed project returns 0 findings.
The file changes the answer. A licence URL pointing at opensource.org/licenses/MIT gets the MIT expression as its fix. A Directory.Build.props that sets both an expression and a file gets a conflict error. An SVG icon is rejected because NuGet takes only PNG and JPEG.
The single-file check is free in VS Code and on the web page, with every rule and every fix. The paid version scans every project in a workspace and exports a dated pack-readiness report per package; a team key adds a CI gate that fails a release on any error.
NuGet Pack Gate reads a .csproj, .fsproj, .vbproj or Directory.Build.props and flags pack metadata that breaks or degrades a nuget.org release: PackageLicenseUrl (NU5125), PackageIconUrl without PackageIcon (NU5048), licence expressions that are not SPDX or not OSI/FSF approved, icon, readme and licence files that are never packed, and net8.0 or net9.0 targets. Each finding shows the replacement line.
It is for .NET library authors and maintainers who publish packages to nuget.org or an internal feed, and for teams moving older csproj files off PackageLicenseUrl and PackageIconUrl. It matters most this quarter for anyone still targeting net8.0 or net9.0, which Microsoft's .NET support policy lists with end of support on November 10, 2026.
dotnet pack prints NU5125 and NU5048 as warnings after a full build, one project at a time, so a default build still passes and the warnings scroll past in CI logs. It says nothing today about net8.0 and net9.0 ending support on November 10, 2026, and a pushed nuget.org version cannot be deleted, only unlisted.
The free version runs all 10 rules on the open project file in VS Code and on the web page, with the fix line on every finding and no cap. The paid version, $29 once with one licence key per person or team seat, scans every project in the workspace and exports a dated pack-readiness report per package; a team key adds a CI gate.
nuget.org does not support permanent deletion of packages. A version pushed with an invalid licence, a missing readme or no icon can only be unlisted, and it still restores for anyone who pins that exact version, so the fix costs a new version number. The single-file check here is free and takes seconds.
One question, answered by the person who built it. Your email only if you want the answer sent.