syncfusion-blazor-docx-editor

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/spell-check.md

The code is consistent with a legitimate spell-check integration and contains no apparent malicious payload or intentional obfuscation. However, the AllowAllOrigins policy, lack of visible authentication and input limits, and client-controlled AddWord operation create security and privacy risks if deployed beyond a trusted environment. Restrict CORS origins, authenticate and authorize requests, validate and limit text size, rate-limit endpoints, and separately authorize dictionary updates.

Confidence: 96%Severity: 55%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:02 AM
Package URL
pkg:socket/skills-sh/syncfusion%2Fdocx-editor-sdk-skills%2Fsyncfusion-blazor-docx-editor%2F@24700167a277a7850268f81aacfe2721b20eb12900f65b4f7475a8ca07369339
Security Audit — socket — syncfusion-blazor-docx-editor