registry  /  pptx-glimpse  /  3.0.0

pptx-glimpse@3.0.0

⚠ Under review

A lightweight JavaScript library for rendering PowerPoint (.pptx) files as SVG or PNG in Node.js. No LibreOffice required.

Static Scan Results

scanned 16h ago · by rust-scanner

Static analysis flagged 7 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
High-risk behavior combination matched malicious policy.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessFilesystem
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 11 file(s), 1.38 MB of source, external domains: prosemirror.net, purl.oclc.org, schemas.microsoft.com, schemas.openxmlformats.org, www.w3.org

Source & flagged code

2 flagged · loading source
dist/browser.cjsView file
12836contains invisible/control Unicode U+200B (zero width space) Get the _n_<U+200B>th outgoing edge from this node in the finite
Critical
Trojan Source Unicode

Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.

dist/browser.cjsView on unpkg · L12836
dist/browser.jsView file
Trigger-reachable chain: manifest.exports -> dist/browser.js Reachable file contains a blocking source-risk pattern.
Critical
Trigger Reachable Dangerous Capability

A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.

dist/browser.jsView on unpkg

Findings

2 Critical1 Medium4 Low
CriticalTrojan Source Unicodedist/browser.cjs
CriticalTrigger Reachable Dangerous Capabilitydist/browser.js
MediumStructural Risk Force Deep Review
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings