registry  /  @vtj/renderer  /  0.18.14

@vtj/renderer@0.18.14

⚠ Under review

VTJ 是一款基于 Vue3 + Typescript 的低代码页面可视化设计器。内置低代码引擎、渲染器和代码生成器,面向前端开发者,开箱即用。 无缝嵌入本地开发工程,不改变前端开发流程和编码习惯。

Static Scan Results

scanned 1d ago · by rust-scanner

Static analysis flagged 8 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
High-risk behavior combination matched malicious policy.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessEvalNetwork
Supply chain
HighEntropyStringsMinifiedUrlStrings
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 401 KB of source, external domains: bugzilla.mozilla.org

Source & flagged code

3 flagged · loading source
dist/index.cjsView file
16}); L17: `;return r.evaluate(n)}Object.defineProperty(jt,"__IS_FUNCTION_FUNC",{value:!0,writable:!1,enumerable:!1,configurable:!1});class Y{constructor(e){this.value=e}}class ue{constructor... L18: `)+a;const u=r?`
Low
Eval

Package source references a known benign dynamic code generation pattern.

dist/index.cjsView on unpkg · L16
dist/index.mjsView file
6450contains invisible/control Unicode U+200C (zero width non-joiner) Oi as isAssignment<U+200C>,
Critical
Trojan Source Unicode

Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.

dist/index.mjsView on unpkg · L6450
Trigger-reachable chain: manifest.module -> dist/index.mjs Reachable file contains a blocking source-risk pattern.
Critical
Trigger Reachable Dangerous Capability

A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.

dist/index.mjsView on unpkg

Findings

2 Critical2 Medium4 Low
CriticalTrojan Source Unicodedist/index.mjs
CriticalTrigger Reachable Dangerous Capabilitydist/index.mjs
MediumNetwork
MediumStructural Risk Force Deep Review
LowScripts Present
LowEvaldist/index.cjs
LowHigh Entropy Strings
LowUrl Strings