prava-sdk-integration
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalyreferences/session-api-reference.md
LOWAnomalyLOW
references/session-api-reference.md
The visible fragment appears to implement a payment-session polling and integration guide rather than malware. It contains a sensitive credential flow: custom-mode results expose a token, dynamic CVV, and expiry fields for subsequent processor submission. This is a significant security and compliance boundary, but the code includes no visible obfuscation, command execution, secret harvesting, or covert exfiltration. Trust in the external payment domain and safety of omitted request/call-site code require independent verification.
Confidence: 88%Severity: 62%
Audit Metadata