A video editing library for creating and editing videos with Shotstack
Loading a WOFF2 font fetches executable JavaScript from a third-party CDN and evaluates it. This is a real remote-code-execution supply-chain risk, but it is not automatically triggered at npm install.
The scanner resource watchdog stopped semantic analysis before full coverage; route this package to AI without publishing a static verdict.
The runtime downloads JavaScript from unpkg and executes it with the Function constructor when it handles a WOFF2 font.
dist/shotstack-studio.es.jsView on unpkg · L44410This report applies to @shotstack/shotstack-studio@2.19.2.
See version security history for other recorded verdicts.
Evidence last updated: .
The scanner resource watchdog stopped semantic analysis before full coverage; route this package to AI without publishing a static verdict.
The runtime downloads JavaScript from unpkg and executes it with the Function constructor when it handles a WOFF2 font.
dist/shotstack-studio.es.jsView on unpkg · L44410