fluentcart-downloads-storage

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/download-delivery.md

No malicious code is present in the supplied documentation. It identifies a potentially significant authorization and entitlement-enforcement gap in FluentCart 1.6.0: the active signed download route reportedly omits ownership, variation, limit/expiry, and download-permission accounting checks. Review the actual FileDownloader, URL generation, hook registration, and storage-driver implementations before deployment, and add atomic enforcement if those guarantees are required.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 07:08 PM
Package URL
pkg:socket/skills-sh/lonsdale201%2Fwp-agent-skills%2Ffluentcart-downloads-storage%2F@359e7376bb4191c57a4b5c4450cabdd819c3536f5fa54c8cf9b2e07ef2af120d
Security Audit — socket — fluentcart-downloads-storage