An SDK to develop applications on the Verified Network
The SDK exports a gasless transaction path that reads an Ethers signer's private key and transmits it to a remote service. A quote path additionally embeds that key in a request URL.
Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgGasless contract calls extract the local signer's private key and send it to a remote sponsorship service.
dist/contract/index.jsView on unpkg · L378The sponsorship POST body includes the private key field.
dist/contract/index.jsView on unpkg · L226The sponsorship POST body includes the private key field.
dist/utils/constants.jsView on unpkg · L5This report applies to @verified-network/verified-sdk@2.9.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgThe sponsorship POST body includes the private key field.
dist/contract/index.jsView on unpkg · L226Gasless contract calls extract the local signer's private key and send it to a remote sponsorship service.
dist/contract/index.jsView on unpkg · L378The sponsorship POST body includes the private key field.
dist/utils/constants.jsView on unpkg · L5