cloudflare-zero-trust-access
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritytemplates/multi-tenant.ts
MEDIUMSecurityMEDIUM
templates/multi-tenant.ts
No direct evidence of malicious code or supply-chain malware is present. The primary risks are severe missing authorization on tenant administration endpoints, exposure of tenant configuration, lack of input validation, and dynamic use of a database-controlled Cloudflare Access domain. The fragment is also syntactically incomplete. SQL queries use parameter binding, but the application should protect admin routes, validate tenant fields and allowed domains, avoid returning sensitive configuration, and avoid exposing internal error messages.
Confidence: 98%Severity: 78%
Audit Metadata