postiz

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
crawlchat.js

This module is a straightforward third-party widget loader. It does not show overt malicious logic in the snippet itself, but it dynamically executes external JavaScript from a third-party domain without integrity/SRI verification and passes a hardcoded tenant/identifier via data attributes. The main risk is supply-chain/trust: if the hosted embed script is compromised or behaves maliciously, it could affect the hosting page.

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
May 5, 2026, 06:26 AM
Package URL
pkg:socket/skills-sh/gitroomhq%2Fpostiz-docs%2Fpostiz%2F@6e494746f024eb919e3e765c17057c69637b03fc