wix-base44-headless
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
SecuritySecuritytemplates/storefront/TEMPLATE.md
MEDIUMSecurityMEDIUM
templates/storefront/TEMPLATE.md
The fragment is an orchestration wrapper that dynamically reads and executes an internal seed module from a fixed absolute path using new Function, then invokes setupStore with an authorization token to perform Wix storefront seeding. While the wrapper itself shows no explicit data theft/exfiltration, the dynamic code execution mechanism substantially increases supply-chain risk: any tampering of the seed-store.js artifact would be executed with the current Node process’s privileges and could perform unauthorized actions against Wix or access local/network resources. Treat as high review priority and verify integrity/contents of the loaded seed-store.js and its outbound behaviors.
Confidence: 62%Severity: 74%
Audit Metadata