syncfusion-javascript-accordion

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/templates.md

The code is documentation and example UI code, not apparent malware. It contains a real XSS and attribute-injection risk pattern because local or API-derived values are inserted directly into HTML and inline JavaScript handlers. Consumers should escape values by context, sanitize intentionally allowed HTML, validate URLs and identifiers, and avoid inline event handlers. No evidence of data theft, backdoors, sabotage, or obfuscation is present.

Confidence: 98%Severity: 57%
AnomalyLOW
references/advanced-use-cases.md

The fragment appears to be benign wizard-form documentation, not malware. It has a meaningful DOM XSS risk in showSummary because untrusted form data is inserted through innerHTML, and it presents a privacy/security concern by persisting potentially sensitive wizard data in localStorage. Use textContent or explicit escaping for the summary, validate parsed state, and avoid storing payment or authentication secrets in localStorage. Assessment is limited to the supplied portion.

Confidence: 94%Severity: 56%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:56 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Fjavascript-ui-controls-skills%2Fsyncfusion-javascript-accordion%2F@68b33bc425a822ded2f540ab8afb9c2b7b1e7cfad80acfcced3ab9b6295ac914
Security Audit — socket — syncfusion-javascript-accordion