security-documentation
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecurityreferences/1-secure-coding-practices.md
MEDIUMSecurityMEDIUM
references/1-secure-coding-practices.md
The fragment is primarily educational secure-coding guidance and contains no evident malware or supply-chain backdoor. The createUserBad example is intentionally vulnerable to SQL injection and must not be used. The CSP configuration is weaker than recommended because it permits unsafe-inline. The parameterized query and DOMPurify allowlist provide appropriate protections in the corresponding secure examples.
Confidence: 99%Severity: 72%
Audit Metadata