pdf-to-text
Audited by Socket on Sep 28, 2026
1 alert found:
SecurityThis is a CDN-driven self-updater/installer whose primary security weakness is supply-chain trust: the script downloads and executes a platform-specific binary from a remote location with no cryptographic integrity/authenticity verification, and it extracts untrusted tar archives with minimal hardening and only superficial post-install validation. No explicit backdoor/exfiltration logic is visible in this wrapper, but if the CDN content or release artifact is tampered with, the executed payload would run directly under the user account. Strongly consider adding signature/checksum verification (and ideally hardened/tar-safe extraction plus stronger content validation) before executing downloaded binaries.