experience-lwc-legacy-migrate
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
AnomalyAnomalyassets/lo20-host-page-template.html
LOWAnomalyLOW
assets/lo20-host-page-template.html
The code is a legitimate-looking Salesforce Lightning Out host-page template and contains no clear malware, exfiltration, persistence, or system-level sabotage. It has meaningful browser security weaknesses: untrusted postMessage/BroadcastChannel/storage data is accepted without origin or integrity validation, frontdoorUrl is passed to the authentication component without allowlisting, and error text is inserted through innerHTML, enabling potential DOM XSS. Replace innerHTML with textContent, validate message origin and source, validate frontdoor URLs against the expected Salesforce origin and HTTPS scheme, and avoid storing sensitive authentication results in localStorage where possible.
Confidence: 97%Severity: 62%
Audit Metadata