registry  /  @misiki/kitcommerce-core  /  0.1.14

@misiki/kitcommerce-core@0.1.14

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 6 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
SourceNo risky source behavior triggered.
Supply chain
HighEntropyStringsUrlStrings
Manifest
NoLicense
scanned 89 file(s), 194 KB of source, external domains: cdn1-sandbox.affirm.com, cdn1.affirm.com, checkout.razorpay.com, s3.ap-south-1.amazonaws.com, schema.org, sdk.cashfree.com, wa.me

Source & flagged code

1 flagged · loading source
dist/composables/use-login.svelte.jsView file
101patternName = generic_password severity = medium line = 101 matchedText = this.pas...t1';
Medium
Secret Pattern

Package contains a possible secret pattern.

dist/composables/use-login.svelte.jsView on unpkg · L101

Findings

1 Medium5 Low
MediumSecret Patterndist/composables/use-login.svelte.js
LowNon Install Lifecycle Scripts
LowScripts Present
LowHigh Entropy Strings
LowUrl Strings
LowNo License