security-best-practice
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecurityrules/input-validation.md
MEDIUMSecurityMEDIUM
rules/input-validation.md
The fragment demonstrates intentionally vulnerable web-application code alongside remediation examples. It contains significant application security risks if the BAD snippets are executed: query/operator injection, open redirect, Host-header poisoning, SSRF, DOM XSS, and mass assignment. The visible content does not indicate malicious package behavior or supply-chain malware, and it is not intentionally obfuscated. Assessment is limited to the supplied fragment; omitted code could alter the overall context.
Confidence: 98%Severity: 72%
Audit Metadata