registry  /  @xplor-education/react-wrappers  /  5.0.1

@xplor-education/react-wrappers@5.0.1

⚠ Under review

React component wrappers for the Xplor design system

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 10 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
High-risk behavior combination matched malicious policy.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessNetwork
Supply chain
HighEntropyStringsProtestwareTelemetryUrlStrings
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 2.76 MB of source, external domains: developer.mozilla.org, google.com, images.unsplash.com, prosemirror.net, stenciljs.com, w3c.github.io, www.w3.org

Source & flagged code

2 flagged · loading source
dist/index.jsView file
33255contains invisible/control Unicode U+200B (zero width space) Get the _n_<U+200B>th outgoing edge from this node in the finite
Critical
Trojan Source Unicode

Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.

dist/index.jsView on unpkg · L33255
Trigger-reachable chain: manifest.module -> dist/index.js Reachable file contains a blocking source-risk pattern.
Critical
Trigger Reachable Dangerous Capability

A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.

dist/index.jsView on unpkg

Findings

2 Critical3 Medium5 Low
CriticalTrojan Source Unicodedist/index.js
CriticalTrigger Reachable Dangerous Capabilitydist/index.js
MediumNetwork
MediumProtestware
MediumStructural Risk Force Deep Review
LowNon Install Lifecycle Scripts
LowScripts Present
LowHigh Entropy Strings
LowTelemetry
LowUrl Strings