crypto-payments

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
references/callback-route-hardening.md

The fragment contains no apparent malicious behavior or supply-chain payload. It provides legitimate webhook hardening and payment-crediting guidance, but includes security-relevant implementation hazards: ambiguous or potentially inverted CSRF matcher semantics, insufficient validation of proxy-hop configuration, possible repeated refund/hold processing, and a likely duplicate-credit bug because creditUser executes after a unique grant violation. The code should not be treated as safe without verifying middleware semantics and making grant/refund operations explicitly idempotent.

Confidence: 94%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 03:59 AM
Package URL
pkg:socket/skills-sh/ssheleg%2Fsheleg-dev%2Fcrypto-payments%2F@791070ec4151617fac3d1d109792cfc923086e4e19c5458bd1450cfb2f5d17e9
Security Audit — socket — crypto-payments