wcs-renewal-scheduler

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
programmatic-renewal.md

The code is a readable WooCommerce renewal skeleton with no apparent malware, credential theft, exfiltration, obfuscated payload, or destructive behavior. It performs sensitive renewal and payment-related operations, so deploying it without authentication, authorization, nonce and replay protection, atomic durable locking, audit logging, idempotency, and recent-order checks would create a meaningful security and billing risk. Raw exception propagation should also be restricted or sanitized.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Sep 9, 2026, 07:09 PM
Package URL
pkg:socket/skills-sh/lonsdale201%2Fwp-agent-skills%2Fwcs-renewal-scheduler%2F@0ba31e1ed0e9bceb44fdeae87bce14e384216534bb6300d8c62e5d632478553d
Security Audit — socket — wcs-renewal-scheduler