No confirmed malicious attack surface. At Hexo generation/runtime, it renders carousel markup and loads package-aligned browser assets.
Static reason
No blocking static signals were detected.
Trigger
User enables the Hexo plugin or uses its swiper/slide tags.
Impact
Adds configured carousel HTML, styles, and JavaScript to the user's site.
Mechanism
Hexo template injection and browser carousel initialization.
Rationale
Source inspection shows a Hexo/Swiper presentation plugin without install-time mutation, exfiltration, remote payload execution, or persistence. Its CDN references are package-aligned assets used for the documented carousel runtime.
Evidence
package.jsonindex.jslib/swiper_init.jslib/slider.njklib/swiper.njklib/swiper.min.js
Network endpoints1
cdn.jsdelivr.net/npm/hexo-shoka-swiper@0.1.12