upstash-redis-js

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Security
SecurityMEDIUM
patterns/session-management.md

The fragment is a readable Redis session-management example and does not show malware, data theft, persistence, or suspicious external communication. It contains a critical authentication risk if the included verifyCredentials placeholder is used as real logic, plus replay risk for remember-me tokens, insufficient input validation for Redis key components, stale multi-device indexes, and non-atomic updates. The authentication helper must be replaced before production use.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 21, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/upstash%2Fskills%2Fupstash-redis-js%2F@a2e6887257bee321bded1241818234cd97d6352a5a40598521019e5709834b27
Security Audit — socket — upstash-redis-js