No confirmed malicious attack surface. The package generates a Hexo carousel and loads its browser assets from its versioned CDN path.
Static reason
No blocking static signals were detected.
Trigger
User enables the Hexo plugin or renders its swiper tags.
Impact
Adds carousel HTML, CSS, and JavaScript to the generated site.
Mechanism
Hexo template injection and Swiper UI initialization.
Rationale
Source inspection shows a package-aligned Hexo/Swiper presentation plugin with no concrete malicious chain or install-time mutation. Its CDN loading and DOM injection are the stated carousel functionality.
Evidence
package.jsonindex.jslib/swiper_init.jslib/slider.njklib/swiper.njkjs/swiper.js
Network endpoints1
cdn.jsdelivr.net/npm/hexo-shoka-swiper@0.1.14