registry  /  nexious-library  /  3.3.4

nexious-library@3.3.4

React component library powering companyuno.com. Includes Calendar, Form, Dialog, Navigation, Checkout components and more.

Static Scan Results

scanned 1d ago · by rust-scanner

Static analysis flagged 7 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
EnvironmentVars
Supply chain
HighEntropyStrings
ManifestNo manifest risk signals triggered.
scanned 198 file(s), 238 KB of source

Source & flagged code

3 flagged · loading source
dist/esm/utils/form/types.jsView file
2patternName = generic_password severity = medium line = 2 matchedText = password...rd",
Medium
Secret Pattern

Package contains a possible secret pattern.

dist/esm/utils/form/types.jsView on unpkg · L2
dist/esm/utils/form/labels.jsView file
13patternName = generic_password severity = medium line = 13 matchedText = password...rd",
Medium
Secret Pattern

Hardcoded password in dist/esm/utils/form/labels.js

dist/esm/utils/form/labels.jsView on unpkg · L13
dist/esm/utils/form/placeholders.jsView file
14patternName = generic_password severity = medium line = 14 matchedText = password.....",
Medium
Secret Pattern

Hardcoded password in dist/esm/utils/form/placeholders.js

dist/esm/utils/form/placeholders.jsView on unpkg · L14

Findings

4 Medium3 Low
MediumSecret Patterndist/esm/utils/form/types.js
MediumEnvironment Vars
MediumSecret Patterndist/esm/utils/form/labels.js
MediumSecret Patterndist/esm/utils/form/placeholders.js
LowNon Install Lifecycle Scripts
LowScripts Present
LowHigh Entropy Strings