registry  /  pdf-oxide-wasm  /  0.3.72

pdf-oxide-wasm@0.3.72

Fast, zero-dependency PDF toolkit for Node.js, browsers, and edge runtimes — text extraction, markdown/HTML conversion, search, form filling, creation, and editing. Rust core compiled to WebAssembly.

Static Scan Results

scanned 4h ago · by rust-scanner

Static analysis flagged 10 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessFilesystemNetwork
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 4 file(s), 821 KB of source

Source & flagged code

8 flagged · loading source
nodejs/pdf_oxide.jsView file
631patternName = private_key_rsa severity = critical line = 631 matchedText = * `keyPe...--`.
Critical
Critical Secret

Package contains a critical-looking secret pattern.

nodejs/pdf_oxide.jsView on unpkg · L631
631patternName = private_key_rsa severity = critical line = 631 matchedText = * `keyPe...--`.
Critical
Secret Pattern

RSA private key in nodejs/pdf_oxide.js

nodejs/pdf_oxide.jsView on unpkg · L631
nodejs/pdf_oxide_bg.wasmView file
path = nodejs/pdf_oxide_bg.wasm kind = wasm_module sizeBytes = 17400783 magicHex = [redacted]
Medium
Ships Wasm Module

Package ships WebAssembly modules.

nodejs/pdf_oxide_bg.wasmView on unpkg
nodejs/pdf_oxide.d.tsView file
259patternName = private_key_rsa severity = critical line = 259 matchedText = * `keyPe...--`.
Critical
Secret Pattern

RSA private key in nodejs/pdf_oxide.d.ts

nodejs/pdf_oxide.d.tsView on unpkg · L259
web/pdf_oxide.jsView file
623patternName = private_key_rsa severity = critical line = 623 matchedText = * `keyPe...--`.
Critical
Secret Pattern

RSA private key in web/pdf_oxide.js

web/pdf_oxide.jsView on unpkg · L623
web/pdf_oxide.d.tsView file
259patternName = private_key_rsa severity = critical line = 259 matchedText = * `keyPe...--`.
Critical
Secret Pattern

RSA private key in web/pdf_oxide.d.ts

web/pdf_oxide.d.tsView on unpkg · L259
bundler/pdf_oxide_bg.jsView file
621patternName = private_key_rsa severity = critical line = 621 matchedText = * `keyPe...--`.
Critical
Secret Pattern

RSA private key in bundler/pdf_oxide_bg.js

bundler/pdf_oxide_bg.jsView on unpkg · L621
bundler/pdf_oxide.d.tsView file
259patternName = private_key_rsa severity = critical line = 259 matchedText = * `keyPe...--`.
Critical
Secret Pattern

RSA private key in bundler/pdf_oxide.d.ts

bundler/pdf_oxide.d.tsView on unpkg · L259

Findings

7 Critical2 Medium1 Low
CriticalCritical Secretnodejs/pdf_oxide.js
CriticalSecret Patternnodejs/pdf_oxide.js
CriticalSecret Patternnodejs/pdf_oxide.d.ts
CriticalSecret Patternweb/pdf_oxide.js
CriticalSecret Patternweb/pdf_oxide.d.ts
CriticalSecret Patternbundler/pdf_oxide_bg.js
CriticalSecret Patternbundler/pdf_oxide.d.ts
MediumNetwork
MediumShips Wasm Modulenodejs/pdf_oxide_bg.wasm
LowFilesystem