create-html-report
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalyassets/report.js
LOWAnomalyLOW
assets/report.js
The visible code appears to be a legitimate client-side reporting and visualization framework, not malware. The main security risk is unsafe dynamic code execution in initCalc(), where HTML attributes are compiled with new Function(). This is acceptable only when the report HTML and its data attributes are fully trusted; it should be replaced with a constrained expression parser for untrusted content. Mermaid loose security settings, dynamic CDN dependencies, and some innerHTML-based SVG generation warrant review for untrusted inputs. No evidence of data theft, persistence, system compromise, or sabotage is present.
Confidence: 98%Severity: 62%
Audit Metadata