payment-gateway-integration
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecurityreferences/paypal-integration.md
MEDIUMSecurityMEDIUM
references/paypal-integration.md
The fragment does not exhibit malware or intentional supply-chain attack behavior. It contains a significant payment-integrity weakness: PayPal webhook signatures are not verified before event data can update order state. The client-controlled amount is also risky if trusted by the server. The deprecated dependency should be migrated, but no malicious behavior is evident in the shown code.
Confidence: 96%Severity: 78%
Audit Metadata