payment-gateway-integration

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
references/paypal-integration.md

The fragment does not exhibit malware or intentional supply-chain attack behavior. It contains a significant payment-integrity weakness: PayPal webhook signatures are not verified before event data can update order state. The client-controlled amount is also risky if trusted by the server. The deprecated dependency should be migrated, but no malicious behavior is evident in the shown code.

Confidence: 96%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:04 AM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fpayment-gateway-integration%2F@15d9a73c5dcef35697fd70590f11cc5322472a23a0713e051561e3e0ce8d7705
Security Audit — socket — payment-gateway-integration