registry  /  @quantabit/cms-sdk  /  1.0.3

@quantabit/cms-sdk@1.0.3

QuantaBit CMS SDK - Reusable content, categories, tags, and media management features

Static Scan Results

scanned 3h ago · by rust-scanner

Static analysis flagged 5 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
SourceNo risky source behavior triggered.
Supply chain
HighEntropyStrings
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 199 KB of source

Source & flagged code

2 flagged · loading source
dist/index.esm.jsView file
831patternName = generic_password severity = medium line = 831 matchedText = password...ed',
Medium
Secret Pattern

Package contains a possible secret pattern.

dist/index.esm.jsView on unpkg · L831
dist/index.cjsView file
833patternName = generic_password severity = medium line = 833 matchedText = password...ed',
Medium
Secret Pattern

Hardcoded password in dist/index.cjs

dist/index.cjsView on unpkg · L833

Findings

2 Medium3 Low
MediumSecret Patterndist/index.esm.js
MediumSecret Patterndist/index.cjs
LowNon Install Lifecycle Scripts
LowScripts Present
LowHigh Entropy Strings