syncfusion-javascript-listview

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/nested-lists-navigation.md

The fragment is navigation/UI code with no clear evidence of malware or supply-chain sabotage. It has potential client-side injection risks because untrusted values are interpolated into HTML and breadcrumb text is appended with innerHTML. URL values should be validated and safely encoded, breadcrumb text should use textContent or DOM text insertion, and new-tab navigation should use a safe noopener approach. The assessment is limited to the shown fragment.

Confidence: 97%Severity: 57%
AnomalyLOW
references/data-binding.md

The fragment is benign instructional code rather than malware. It contains notable client-side security risks if copied unchanged: unsanitized remote HTML is inserted with innerHTML, template values are not escaped, and data-derived URLs are fetched without validation. The hardcoded bearer token is an unsafe illustrative practice. Remote content should be sanitized with a trusted HTML sanitizer or rendered as text, URLs should be restricted and validated, response schemas should be checked, and real credentials must not be embedded in client-side code.

Confidence: 99%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:57 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Fjavascript-ui-controls-skills%2Fsyncfusion-javascript-listview%2F@4da8525035c3804b7da327bb8685012266d7258d51e69dbca07f8da3f60e3457
Security Audit — socket — syncfusion-javascript-listview