chrome-extension
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/ui-render-with-cached-data.md
LOWAnomalyLOW
references/ui-render-with-cached-data.md
The code implements a legitimate cache-first popup rendering pattern and contains no clear malware or supply-chain backdoor behavior. However, it unsafely interpolates remote and cached data into innerHTML. data.status should be validated and escaped, or rendered with textContent and controlled DOM APIs; class names should be selected from an allowlist. The security issue is a meaningful injection risk, not evidence of intentional malicious behavior.
Confidence: 98%Severity: 62%
Audit Metadata