purchasely-integrate
Warn
Audited by Snyk on Jul 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The Purchasely skill is explicitly designed to initiate and manage real monetary transactions (in‑app purchases/subscriptions) via platform stores. It documents and exposes concrete APIs for running and processing purchases (Full mode where "the SDK handles the entire purchase flow"), purchase interceptors (.purchase action), restore/purchase APIs (Purchasely.restoreAllProducts(), Purchasely.synchronize()), and guidance for Observer vs Full modes that control whether the SDK or the app executes billing flows. Those are specific purchase/payment execution capabilities (store billing flows / receipt uploads), not generic utilities, so this grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata