fluentcart-downloads-storage
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/download-delivery.md
LOWAnomalyLOW
references/download-delivery.md
No malicious code is present in the supplied documentation. It identifies a potentially significant authorization and entitlement-enforcement gap in FluentCart 1.6.0: the active signed download route reportedly omits ownership, variation, limit/expiry, and download-permission accounting checks. Review the actual FileDownloader, URL generation, hook registration, and storage-driver implementations before deployment, and add atomic enforcement if those guarantees are required.
Confidence: 90%Severity: 62%
Audit Metadata