syncfusion-javascript-rich-text-editor

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/markdown-features.md

The code is ordinary Markdown editor documentation with no clear malicious or supply-chain attack behavior. However, the live preview example has a potential stored or reflected XSS risk because user-controlled Markdown is converted to HTML and assigned directly to innerHTML without sanitization or URL validation. Use a current marked.js release with restrictive options and sanitize the generated HTML before insertion.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:57 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Fjavascript-ui-controls-skills%2Fsyncfusion-javascript-rich-text-editor%2F@7f6c7f5535d9addc74bb7b3bbc6a8760d693008383d58b8f700d6b19a044278a
Security Audit — socket — syncfusion-javascript-rich-text-editor