syncfusion-aspnetcore-docx-editor

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/spell-check.md

The code implements a legitimate spell-checking service and contains no clear malicious behavior, credential theft, obfuscation, or destructive operations. Security concerns are the permissive AllowAllOrigins CORS policy, lack of endpoint authentication/authorization, and direct client control of AddWord, which could permit unauthorized shared dictionary changes depending on library behavior. Restrict CORS, authenticate requests, validate input and language IDs, and separately authorize dictionary modifications.

Confidence: 96%Severity: 56%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:02 AM
Package URL
pkg:socket/skills-sh/syncfusion%2Fdocx-editor-sdk-skills%2Fsyncfusion-aspnetcore-docx-editor%2F@cf051a7eadeb407d82879beed002ad204480caad05c841c9aedfad4e2302f4f7
Security Audit — socket — syncfusion-aspnetcore-docx-editor