apollo-server
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/plugins.md
LOWAnomalyLOW
references/plugins.md
The code is a conventional Apollo Server plugin configuration with no evidence of malware or supply-chain sabotage. The primary security concern is the explicit forwarding of all request headers and GraphQL variable values to Apollo Studio, which may leak secrets or personal data if requests contain them. Header and variable redaction should be configured before production use.
Confidence: 98%Severity: 58%
Audit Metadata