security-nextjs

Fail

Audited by Socket on Jun 18, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/scan.sh

The script is a defensive static analysis tool for Next.js projects. It does not engage in data exfiltration or obfuscation; its purpose is to surface configuration and code patterns that could lead to security issues. While the tool itself appears safe, the detected risks depend on repository content; the most significant concerns are exposed secrets, unauthenticated server/actions, potentially insufficient middleware coverage, and missing security headers.

Confidence: 90%
Audit Metadata
Analyzed At
Jun 18, 2026, 01:54 AM
Package URL
pkg:socket/skills-sh/jal-co%2Fjalco-opencode%2Fsecurity-nextjs%2F@fd1a08c514c182b98b597627924e3f7d9d174b60a960e6d14ac40e7a1cada3d0
Security Audit — socket — security-nextjs