registry  /  @vtj/utils  /  0.18.15

@vtj/utils@0.18.15

VTJ 是一款基于 Vue3 + Typescript 的低代码页面可视化设计器。内置低代码引擎、渲染器和代码生成器,面向前端开发者,开箱即用。 无缝嵌入本地开发工程,不改变前端开发流程和编码习惯。

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 8 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoNetwork
Supply chain
HighEntropyStringsMinifiedObfuscated
ManifestNo manifest risk signals triggered.
scanned 4 file(s), 443 KB of source

Source & flagged code

3 flagged · loading source
dist/index.iife.jsView file
14patternName = private_key_rsa severity = critical line = 14 matchedText = */var B=...erve
Critical
Critical Secret

Package contains a critical-looking secret pattern.

dist/index.iife.jsView on unpkg · L14
14patternName = private_key_rsa severity = critical line = 14 matchedText = */var B=...erve
Critical
Secret Pattern

RSA private key in dist/index.iife.js

dist/index.iife.jsView on unpkg · L14
dist/index.umd.jsView file
14patternName = private_key_rsa severity = critical line = 14 matchedText = */var B=...erve
Critical
Secret Pattern

RSA private key in dist/index.umd.js

dist/index.umd.jsView on unpkg · L14

Findings

3 Critical2 Medium3 Low
CriticalCritical Secretdist/index.iife.js
CriticalSecret Patterndist/index.iife.js
CriticalSecret Patterndist/index.umd.js
MediumNetwork
MediumStructural Risk Force Deep Review
LowScripts Present
LowObfuscated
LowHigh Entropy Strings