pe-verify

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/report-template.html

The fragment is a legitimate report-viewer UI and contains no evident malware. It has two security concerns: unsafe direct insertion of the report JSON template and unescaped item IDs used in innerHTML-generated attributes. These should be fixed by safely serializing the data (for example, JSON.stringify with appropriate HTML-safe embedding) and escaping or DOM-constructing all identifier attributes. External media URLs may enable ordinary browser tracking if report data points to third-party hosts.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Aug 30, 2026, 08:05 PM
Package URL
pkg:socket/skills-sh/backnotprop%2Fproduct-engineering%2Fpe-verify%2F@86cc9c7c2d23419c825fef79ce006088df7c07ceef28042984391f5b6ce447ea
Security Audit — socket — pe-verify