shopware6

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
references/app-system.md

The fragment does not show intentional malware or supply-chain sabotage. The primary security defect is the unauthenticated /shopware/confirm endpoint, which accepts and persists API credentials based only on a caller-supplied shopId. Add authenticated confirmation verification and bind it to the preceding registration, validate payloads and shop existence, and protect the Admin API request with strict HTTPS URL validation and redirect controls. Also reject unknown webhook shops and minimize the high-impact permissions shown in the example.

Confidence: 96%Severity: 72%
Audit Metadata
Analyzed At
Aug 27, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/dpaguba%2Fshopware-skill%2Fshopware6%2F@4d157cc57949a8b7a1eeaceff61e2cff0b25c40b7e43dfae5d2e36a2199955cc
Security Audit — socket — shopware6