service-concierge-portal-generate
Audited by Socket on Aug 27, 2026
1 alert found:
AnomalyNo clear evidence of traditional supply-chain malware (no obfuscation-driven payloads, no exfiltration, no backdoor/persistence mechanisms) is present in the provided fragment. However, the code intentionally performs high-impact security posture weakening on the deployed Experience Cloud site by disabling Locker, enabling relaxed CSP, and setting clickjacking protection to allow all framing. This materially increases the attack surface and should be treated as a significant security-risk configuration change that must be strictly scoped to only the required sites/conditions and validated to apply only to intended org targets. Overall: low likelihood of malware, elevated security risk due to deliberate browser-defense reduction.