registry  /  admin-ui-starter-kit  /  0.6.2

admin-ui-starter-kit@0.6.2

Opinionated React component kit for admin panels and SaaS dashboards, built on top of shadcn/ui + Tailwind CSS v4. Callback-driven, framework-agnostic, i18n-ready.

Static Scan Results

scanned 4d ago · by rust-scanner

Static analysis flagged 18 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessFilesystemNetwork
Supply chain
HighEntropyStringsMinifiedObfuscatedProtestwareTelemetryUrlStrings
ManifestNo manifest risk signals triggered.
scanned 639 file(s), 6.91 MB of source, external domains: api.dicebear.com, base-ui.com, bit.ly, carto.com, example.com, github.com, i.pravatar.cc, images.unsplash.com, leafletjs.com, local.invalid, photon.komoot.io, prosemirror.net, radix-ui.com, react.dev, redux-toolkit.js.org, redux.js.org, status.example.com, vitejs.dev, www.google.com, www.openstreetmap.org, www.typescriptlang.org, www.w3.org

Source & flagged code

8 flagged · loading source
dist/showcase/assets/api-key-list-wxmuRN1m.jsView file
1patternName = stripe_live_secret severity = critical line = 1 matchedText = import{n...ct';
Critical
Critical Secret

Package contains a critical-looking secret pattern.

dist/showcase/assets/api-key-list-wxmuRN1m.jsView on unpkg · L1
1patternName = stripe_live_secret severity = critical line = 1 matchedText = import{n...ct';
Critical
Secret Pattern

Stripe live secret key in dist/showcase/assets/api-key-list-wxmuRN1m.js

dist/showcase/assets/api-key-list-wxmuRN1m.jsView on unpkg · L1
31patternName = stripe_live_secret severity = critical line = 31 matchedText = { id: 'l...' },
Critical
Secret Pattern

Stripe live secret key in dist/showcase/assets/api-key-list-wxmuRN1m.js

dist/showcase/assets/api-key-list-wxmuRN1m.jsView on unpkg · L31
1patternName = stripe_test_secret severity = high line = 1 matchedText = import{n...ct';
High
Secret Pattern

Stripe test secret key in dist/showcase/assets/api-key-list-wxmuRN1m.js

dist/showcase/assets/api-key-list-wxmuRN1m.jsView on unpkg · L1
32patternName = stripe_test_secret severity = high line = 32 matchedText = { id: 't...' },
High
Secret Pattern

Stripe test secret key in dist/showcase/assets/api-key-list-wxmuRN1m.js

dist/showcase/assets/api-key-list-wxmuRN1m.jsView on unpkg · L32
dist/files/inter-latin-ext-wght-normal.woff2View file
path = dist/files/inter-latin-ext-wght-normal.woff2 kind = high_entropy_blob sizeBytes = 85068 magicHex = [redacted]
High
Ships High Entropy Blob

Package ships high-entropy non-source blobs.

dist/files/inter-latin-ext-wght-normal.woff2View on unpkg
.agents/skills/component-library-rules/references/components/composed__api-key-list.mdView file
71patternName = stripe_live_secret severity = critical line = 71 matchedText = { id: 'l...' },
Critical
Secret Pattern

Stripe live secret key in .agents/skills/component-library-rules/references/components/composed__api-key-list.md

.agents/skills/component-library-rules/references/components/composed__api-key-list.mdView on unpkg · L71
72patternName = stripe_test_secret severity = high line = 72 matchedText = { id: 't...' },
High
Secret Pattern

Stripe test secret key in .agents/skills/component-library-rules/references/components/composed__api-key-list.md

.agents/skills/component-library-rules/references/components/composed__api-key-list.mdView on unpkg · L72

Findings

4 Critical4 High3 Medium7 Low
CriticalCritical Secretdist/showcase/assets/api-key-list-wxmuRN1m.js
CriticalSecret Patterndist/showcase/assets/api-key-list-wxmuRN1m.js
CriticalSecret Patterndist/showcase/assets/api-key-list-wxmuRN1m.js
CriticalSecret Pattern.agents/skills/component-library-rules/references/components/composed__api-key-list.md
HighShips High Entropy Blobdist/files/inter-latin-ext-wght-normal.woff2
HighSecret Patterndist/showcase/assets/api-key-list-wxmuRN1m.js
HighSecret Patterndist/showcase/assets/api-key-list-wxmuRN1m.js
HighSecret Pattern.agents/skills/component-library-rules/references/components/composed__api-key-list.md
MediumNetwork
MediumProtestware
MediumStructural Risk Force Deep Review
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowObfuscated
LowHigh Entropy Strings
LowTelemetry
LowUrl Strings