registry  /  @urbicon-ui/auth  /  6.19.0

@urbicon-ui/auth@6.19.0

Authentication for SvelteKit — JWT sessions, passkeys/WebAuthn, notifications and email with zero runtime dependencies

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 12 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
CryptoDynamicRequireFilesystemNetwork
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 100 file(s), 429 KB of source, external domains: api.lettermint.co, push.test, sanitize-redirect.internal

Source & flagged code

7 flagged · loading source
dist/i18n/de.jsView file
33patternName = generic_password severity = medium line = 33 matchedText = password...rt',
Medium
Secret Pattern

Package contains a possible secret pattern.

dist/i18n/de.jsView on unpkg · L33
47patternName = generic_password severity = medium line = 47 matchedText = password...rt',
Medium
Secret Pattern

Hardcoded password in dist/i18n/de.js

dist/i18n/de.jsView on unpkg · L47
74patternName = generic_password severity = medium line = 74 matchedText = password...rt',
Medium
Secret Pattern

Hardcoded password in dist/i18n/de.js

dist/i18n/de.jsView on unpkg · L74
dist/server/password.jsView file
85try { L86: const mod = (await import(/* @vite-ignore */ specifier)); L87: return (password, hash) => mod.compare(password, hash);
Medium
Dynamic Require

Package source references dynamic require/import behavior.

dist/server/password.jsView on unpkg · L85
dist/i18n/en.jsView file
33patternName = generic_password severity = medium line = 33 matchedText = password...rd',
Medium
Secret Pattern

Hardcoded password in dist/i18n/en.js

dist/i18n/en.jsView on unpkg · L33
47patternName = generic_password severity = medium line = 47 matchedText = password...rd',
Medium
Secret Pattern

Hardcoded password in dist/i18n/en.js

dist/i18n/en.jsView on unpkg · L47
74patternName = generic_password severity = medium line = 74 matchedText = password...rd',
Medium
Secret Pattern

Hardcoded password in dist/i18n/en.js

dist/i18n/en.jsView on unpkg · L74

Findings

8 Medium4 Low
MediumSecret Patterndist/i18n/de.js
MediumDynamic Requiredist/server/password.js
MediumNetwork
MediumSecret Patterndist/i18n/de.js
MediumSecret Patterndist/i18n/de.js
MediumSecret Patterndist/i18n/en.js
MediumSecret Patterndist/i18n/en.js
MediumSecret Patterndist/i18n/en.js
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings