syncfusion-blazor-docx-editor
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/spell-check.md
LOWAnomalyLOW
references/spell-check.md
The code is consistent with a legitimate spell-check integration and contains no apparent malicious payload or intentional obfuscation. However, the AllowAllOrigins policy, lack of visible authentication and input limits, and client-controlled AddWord operation create security and privacy risks if deployed beyond a trusted environment. Restrict CORS origins, authenticate and authorize requests, validate and limit text size, rate-limit endpoints, and separately authorize dictionary updates.
Confidence: 96%Severity: 55%
Audit Metadata