klaviyo-data-handling
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/implementation.md
LOWAnomalyLOW
references/implementation.md
The code implements legitimate Klaviyo privacy and consent operations and contains no clear malware or supply-chain backdoor. The primary security issue is an injection risk from interpolating an unescaped email into the DSAR filter. Additional privacy risks arise from incomplete secret redaction, raw or partially redacted identifiers in logs, shallow redaction, and long fixed retention. The irreversible deletion and subscription functions require strong caller authorization and input validation.
Confidence: 97%Severity: 61%
Audit Metadata