experience-lwc-legacy-migrate

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/lo20-host-page-template.html

The code is a legitimate-looking Salesforce Lightning Out host-page template and contains no clear malware, exfiltration, persistence, or system-level sabotage. It has meaningful browser security weaknesses: untrusted postMessage/BroadcastChannel/storage data is accepted without origin or integrity validation, frontdoorUrl is passed to the authentication component without allowlisting, and error text is inserted through innerHTML, enabling potential DOM XSS. Replace innerHTML with textContent, validate message origin and source, validate frontdoor URLs against the expected Salesforce origin and HTTPS scheme, and avoid storing sensitive authentication results in localStorage where possible.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 22, 2026, 04:57 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fexperience-lwc-legacy-migrate%2F@1c09bdb9cd08a3c6a8b8f89092ffd13d1f0a5cb2fa85814deacf688f7fd9b112
Security Audit — socket — experience-lwc-legacy-migrate