paddle-customer-portal
Warn
Audited by Snyk on Jun 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly integrates with Paddle (a payment gateway) and calls the Paddle Node SDK method customerPortalSessions.create using a server-side PADDLE_API_KEY to mint customer portal sessions. Those sessions provide one-time URLs that let customers view invoices, update payment methods, and cancel subscriptions (including per-subscription cancel/update deep links). This is a specific payment-gateway API integration (not a generic HTTP/browser tool) that enables direct management of billing/subscription operations, so it constitutes direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata