tw-payment-integration

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/ecpay-api.md

The fragment appears to be legitimate ECPay payment integration code, not malware. The primary security issue is unescaped user-controlled data in generated HTML form attributes, which can enable XSS. Payment integrity and operational risks also exist if signature validation does not verify all relevant fields, if database locking is used outside a transaction, or if fulfillment is not independently idempotent. No credential theft, malicious payload, suspicious exfiltration, or obfuscation is evident in the supplied portion.

Confidence: 94%Severity: 56%
Audit Metadata
Analyzed At
Sep 18, 2026, 02:08 PM
Package URL
pkg:socket/skills-sh/asgard-ai-platform%2Fskills%2Ftw-payment-integration%2F@0364d3c2f897c9ccc267df079bcb4c761a6fb0bf12941ce4cfb1a66f52e28d59
Security Audit — socket — tw-payment-integration