syncfusion-react-popups

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/predefineddialog-getting-started.md

The code is ordinary UI documentation and does not show intentional malware or supply-chain attack behavior. However, promptOkAction contains a DOM XSS risk because untrusted prompt input is inserted through innerHTML. Use textContent, React rendering, or a trusted sanitizer instead. The remaining code presents no significant malicious behavior.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 04:21 AM
Package URL
pkg:socket/skills-sh/syncfusion%2Freact-ui-components-skills%2Fsyncfusion-react-popups%2F@5b3a2041b830414688e42194337c1a5b81f933c48b2aefae9bc6110d0a208b3f
Security Audit — socket — syncfusion-react-popups