nextjs-ssr

Warn

Audited by Snyk on Jun 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill injects an external script at runtime via the SCRIPT_URL imported from @marsidev/react-turnstile (used as src in ), which will load and execute remote JavaScript (typically the Cloudflare Turnstile script, e.g. https://challenges.cloudflare.com/turnstile/v0/api.js), so this is a runtime dependency that executes remote code.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 05:39 AM
Issues
1
Security Audit — snyk — nextjs-ssr