accessibility-expert
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalyreferences/COMPONENTS.md
LOWAnomalyLOW
references/COMPONENTS.md
The fragment is primarily benign accessibility documentation and example code. The main security issue is an unsafe `innerHTML` assignment in `showErrors` using potentially untrusted error fields and messages, creating a possible DOM XSS vulnerability. Dynamic selectors also require field-name validation or `CSS.escape`. There is no evidence of supply-chain malware or deliberate malicious behavior in the shown code.
Confidence: 98%Severity: 58%
Audit Metadata