registry  /  @xaligo/xaligo  /  0.1.5

@xaligo/xaligo@0.1.5

xaligo CLI and TypeScript/WASM API for rendering .xal diagrams

Static Scan Results

scanned 21h ago · by rust-scanner

Static analysis flagged 12 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessDynamicRequireEnvironmentVarsEvalFilesystemNetwork
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 4 file(s), 1.43 MB of source, external domains: gitbrent.github.io, github.com, purl.org, schemas.microsoft.com, schemas.openxmlformats.org, stuk.github.io, www.w3.org

Source & flagged code

5 flagged · loading source
package.jsonView file
scripts.postinstall = node scripts/npm/install.cjs
High
Install Time Lifecycle Scripts

Package defines install-time lifecycle scripts.

package.jsonView on unpkg
scripts.postinstall = node scripts/npm/install.cjs
Medium
Ambiguous Install Lifecycle Script

Install-time lifecycle script is not statically allowlisted and needs review.

package.jsonView on unpkg
external/dist/index.jsView file
2563if (typeof callback !== "function") { L2564: callback = new Function("" + callback); L2565: }
Low
Eval

Package source references a known benign dynamic code generation pattern.

external/dist/index.jsView on unpkg · L2563
bin/xaligo.cjsView file
3L4: const { spawn } = require('node:child_process'); L5: const fs = require('node:fs');
Medium
Dynamic Require

Package source references dynamic require/import behavior.

bin/xaligo.cjsView on unpkg · L3
external/wasm/xaligo.wasmView file
path = external/wasm/xaligo.wasm kind = wasm_module sizeBytes = 3206995 magicHex = [redacted]
Medium
Ships Wasm Module

Package ships WebAssembly modules.

external/wasm/xaligo.wasmView on unpkg

Findings

1 High6 Medium5 Low
HighInstall Time Lifecycle Scriptspackage.json
MediumAmbiguous Install Lifecycle Scriptpackage.json
MediumDynamic Requirebin/xaligo.cjs
MediumNetwork
MediumEnvironment Vars
MediumShips Wasm Moduleexternal/wasm/xaligo.wasm
MediumStructural Risk Force Deep Review
LowScripts Present
LowEvalexternal/dist/index.js
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings